Junglewise Threat Intelligence

CVE-2026-42735: Iqonic Design KiviCare authentication bypass in password recovery

CVE-2026-42735 · Severity: high · CVSS 8.2 · Published 2026-05-27

Vendors: Iqonic Design.

Executive brief

KiviCare is a clinic management plugin for WordPress used to handle patient records and appointments. A security flaw in the password recovery process allows unauthorized individuals to bypass authentication and potentially take over user accounts, including administrative ones. This could lead to the exposure of sensitive medical data or a complete compromise of the website.

Technical details

An authentication bypass vulnerability (CWE-288) exists in the Iqonic Design KiviCare clinic management system plugin for WordPress through version 4.3.0. The flaw resides in the password recovery logic, where an alternate path or channel can be exploited to bypass standard authentication checks. An unauthenticated remote attacker can leverage this to reset passwords or gain access to high-privileged accounts. The vulnerability is addressed in version 4.4.0.

Affected products

  • Iqonic Design KiviCare Clinic Management System <= 4.3.0

Timeline

  • 2026-04-26: other: Reported by researcher kai63001
  • 2026-05-26: patched: Version 4.4.0 released
  • 2026-05-27: disclosed: CVE published by Patchstack and NVD

References