Record summary

CVE-2026-2992 has a selected CVSS score of 8.2 (high).

Description

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 18, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

KiviCare – Clinic & Patient Management System (EHR)

Browse iqonicdesign / KiviCare – Clinic & Patient Management System (EHR)

Default status: unaffected

CVE ListThrough 4.1.2affected

References

4