📦 Kivicare

by Iqonic

🔍 What is Kivicare?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-0786

CRITICAL CVSS 9.8 Jun 13, 2022

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the KiviCare plugin. It affects all WordPress installations with KiviCare plugin versions...

CVE-2024-11728

HIGH CVSS 7.5 Dec 6, 2024

This SQL injection vulnerability in the KiviCare WordPress plugin allows unauthenticated attackers to execute arbitrary SQL queries through the 'visit_type[service_id]' parameter. Attackers can extrac...

CVE-2023-2628

HIGH CVSS 8.8 Jun 27, 2023

The KiviCare WordPress plugin before version 3.2.1 lacks proper CSRF protection in AJAX endpoints, allowing attackers to trick logged-in administrators into performing unauthorized actions. This affec...

CVE-2024-11730

MEDIUM CVSS 6.5 Dec 6, 2024

This SQL injection vulnerability in the KiviCare WordPress plugin allows authenticated attackers with doctor or receptionist access to execute arbitrary SQL queries. Attackers can extract sensitive da...

CVE-2024-35659

MEDIUM CVSS 5.3 Jun 8, 2024

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the KiviCare WordPress plugin. It allows authenticated users to bypass authorization controls by manipulating object refe...