CVE-2026-13610 is an improper privilege assignment vulnerability in the KiviCare WordPress plugin before version 4.5.2. The plugin's unauthenticated registration endpoint does not adequately restrict which roles can be assigned during account creation. As a result, a remote unauthenticated attacker can register a new account directly with the privileged clinic-staff doctor role instead of a low-privilege or pending role. Successful exploitation yields an active privileged application account with broad access to sensitive healthcare and business data managed by the plugin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a focused Python exploit project for CVE-2026-13610 affecting the WordPress KiviCare – Clinic & Patient Management System plugin up to version 4.5.1. The vulnerability is an unauthenticated privilege-management flaw in the public registration API that allows an attacker to choose privileged staff roles such as kiviCare_doctor or kiviCare_receptionist during account creation. Repository structure is small and purpose-built: exploit.py is the main PoC, preflight.py checks handshake/settings behavior, verify_impact.py demonstrates post-exploitation access to clinical data, README.md documents the bug and usage, and analysis/TECHNICAL_ANALYSIS.md provides detailed root-cause analysis. requirements.txt lists requests and PyNaCl dependencies. The main exploit capability is unauthorized account creation. exploit.py negotiates the plugin's optional REST E2EE transport by calling unauthenticated handshake endpoints (/server-key and /config/register-key), automatically detects whether the target is using plain JSON or encrypted transport, builds a registration payload with attacker-controlled credentials and role, and submits it to POST /wp-json/kivicare/v1/auth/register. It can also verify success by logging in through POST /wp-json/kivicare/v1/auth/login. A second capability is impact validation. verify_impact.py logs in with the created account, captures the returned wp_rest nonce and cookies, rebinds the account's client public key via /config/register-key, and then accesses staff-only endpoints such as /patients and /appointments to prove exposure of patient PHI and appointment data. The exploit is operational rather than merely demonstrative because it contains complete end-to-end logic for transport negotiation, encrypted payload handling, account creation, login verification, and privileged data access. It is not a framework module and not just a detector; it is a working exploit plus verification tooling.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.