Junglewise Threat Intelligence

CVE-2026-40792: KiviCare Clinic Management System IDOR in WordPress plugin

CVE-2026-40792 · Severity: medium · CVSS 6.3 · Published 2026-06-15

Executive brief

KiviCare is a clinic management system for WordPress used to handle patient appointments and medical records. A security flaw in versions 4.2.1 and earlier allows logged-in users with low-level 'Subscriber' permissions to access or modify data they should not be able to see. This could lead to the exposure of sensitive patient information or unauthorized changes to clinic records, potentially impacting patient privacy and operational integrity.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the KiviCare WordPress plugin (versions <= 4.2.1) due to insufficient authorization checks on user-controlled keys (CWE-639). An attacker authenticated with 'Subscriber' level privileges can manipulate object identifiers in network requests to access or modify data belonging to other users or the system. This bypasses intended access controls, potentially allowing unauthorized interaction with the database or access to sensitive files. The issue is resolved in version 4.3.0.

Affected products

  • KiviCare KiviCare Clinic Management System <= 4.2.1

Timeline

  • 2026-03-24: other: Reported by Jakub Herman
  • 2026-04-23: advisory: Patchstack advisory published
  • 2026-04-23: patched: Version 4.3.0 released
  • 2026-06-15: disclosed: NVD publication date

References