Junglewise Threat Intelligence

CVE-2026-15073: KiviCare EHR SQL injection in orderby parameter

CVE-2026-15073 · Severity: medium · CVSS 6.5 · Published 2026-07-11

Technologies: Iqonic Design KiviCare. Vendors: Iqonic Design.

Executive brief

KiviCare is a WordPress plugin used by medical facilities to manage patient records and clinic operations. A security flaw allows authorized staff members, such as doctors or receptionists, to bypass security controls and access sensitive information from the clinic's database that they should not be able to see. This could lead to the exposure of private patient data or internal clinic records.

Technical details

A SQL injection vulnerability exists in the KiviCare WordPress plugin due to insufficient escaping and lack of preparation on the 'orderby' parameter within the KCQueryBuilder.php and DoctorSessionController.php components. The flaw is accessible via a REST API endpoint restricted to users with at least Doctor, Receptionist, or Clinic Admin roles. An attacker can exploit this by appending malicious SQL queries to existing database calls to exfiltrate sensitive data. The issue affects all versions up to 4.5.0; a patch was introduced in changeset 3602561.

Affected products

  • iqonicdesign KiviCare – Clinic & Patient Management System (EHR) up to, and including, 4.5.0

Timeline

  • 2026-07-11: advisory: NVD publication date
  • 2026-07-11: disclosed: Wordfence vulnerability disclosure

References

Related threats