PT-2026-4325 · WordPress · Kivicare – Clinic & Patient Management System

Sarawut Poolkhet

·

Published

2026-01-23

·

Updated

2026-01-23

·

CVE-2026-0927

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress versions through 3.6.15
Description The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is susceptible to unauthorized file uploads. This is due to a lack of proper authorization checks within the uploadMedicalReport() function. This allows unauthenticated attackers to upload text files and PDF documents to the server. Successful exploitation could lead to hosting malicious content or phishing pages through uploaded PDF files.
Recommendations Update KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress to a version later than 3.6.15.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0927

Affected Products

Kivicare – Clinic & Patient Management System