CVE-2026-13613 PUBLISHED

KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint

Assigner: WPScan
Reserved: 29.06.2026 Published: 12.08.2026 Updated: 12.08.2026

The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.

Product Status

Vendor Unknown
Product KiviCare
Versions Default: unaffected
  • affected from 0 to 4.5.2 (excl.)

Credits

  • Mokksh Parekh finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE