CVE-2026-2991 is a critical authentication bypass vulnerability affecting the KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress, in all versions up to 4.1.2. This flaw allows unauthenticated attackers to log in as any patient by exploiting the `patientSocialLogin()` function, which fails to verify social provider access tokens, requiring only an email address and an arbitrary token. This grants full access to sensitive medical records, appointments, and billing information, posing a severe PII/PHI breach risk. Rated 9.8 CRITICAL on the CVSS scale, it has a network attack vector, low complexity, and requires no privileges or user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | >= 0, <= 4.1.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.