CVE-2026-42735

8.2

Iqonic Design · KiviCare

The KiviCare clinic management plugin for WordPress contains an authentication bypass vulnerability that can be exploited during the password recovery process.

Executive summary

The KiviCare WordPress plugin is affected by an authentication bypass vulnerability that allows attackers to potentially compromise user accounts via password recovery.

Vulnerability

This is an authentication bypass vulnerability (CWE-288) utilizing an alternate path or channel. An unauthenticated attacker can exploit this flaw to manipulate the password recovery mechanism and gain unauthorized access to the application.

Business impact

Successful exploitation allows an attacker to take over administrative or user accounts, leading to unauthorized access to sensitive patient data and clinic management systems. With a CVSS score of 8.2, this vulnerability poses a severe risk to data privacy and regulatory compliance in healthcare environments.

Remediation

Immediate Action: Update the KiviCare – Clinic & Patient Management System (EHR) plugin to version 4.4.0 or later immediately.

Proactive Monitoring: Review user account modification logs and password reset requests for suspicious activity or unauthorized account changes.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at the password recovery endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators must update the KiviCare plugin to version 4.4.0 as soon as possible. Given the sensitivity of the data handled by this clinic management system, maintaining an up-to-date installation is critical to preventing unauthorized account access.

More Iqonic Design CVEs