Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19417

Опубликовано: 19 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.

EPSS

Процентиль: 16%
0.00248
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
github
около 1 месяца назад

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.

EPSS

Процентиль: 16%
0.00248
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639