All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-13613
HIGHpublished 2026-08-12 06:17 UTC · 21 hours ago · modified 2026-08-12 20:17 UTC
8.8
CVSS / 10
// description
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.
// weaknesses (CWE)
- CWE-89