Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-378w-q773-hrgh

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

EPSS

Процентиль: 26%
0.00326
Низкий

7.5 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

EPSS

Процентиль: 26%
0.00326
Низкий

7.5 High

CVSS3

Дефекты

CWE-269