CVE-2026-2991 is an authentication bypass vulnerability in the KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress affecting all versions up to and including 4.1.2. The flaw is caused by the patientSocialLogin() function accepting a social-login request without validating the social provider access token before authenticating the user. As a result, an unauthenticated attacker can impersonate any patient account by supplying the victim patient's email address together with an arbitrary token value, bypassing normal credential verification. The available information also indicates that authentication cookies are issued before the application completes its role check. Consequently, even when the application returns an HTTP 403 response for non-patient targets, authentication cookies for those accounts may still be included in the response headers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a real Python proof-of-concept exploit for CVE-2026-2991 affecting the KiviCare Clinic & Patient Management System WordPress plugin <= 4.1.2. The main exploit file is CVE-2026-2991.py, which uses the requests library to interact directly with the KiviCare REST API. Its workflow is straightforward: verify the KiviCare namespace is reachable at /wp-json/kivicare/v1/, then send a crafted POST request to /wp-json/kivicare/v1/auth/patient/social-login using only a target email address, a claimed social provider (google or apple), and a hardcoded fake token. The script interprets 200 responses as successful patient impersonation, prints returned user metadata, extracts auth cookies from the session, and generates a browser-console JavaScript snippet to inject those cookies into the target site. It also handles a notable secondary condition: if the endpoint returns 403 for non-patient accounts, it checks whether Set-Cookie/auth cookies were still issued before role validation and, if so, prints them for replay toward /wp-admin/. Repository structure is small and focused. Besides the exploit script, there is documentation (README, SECURITY, CONTRIBUTING, LICENSE) and a Docker lab under docker/ that builds a reproducible vulnerable environment. The Docker lab provisions WordPress plus the vulnerable KiviCare plugin, waits for MySQL, installs WordPress, enables permalinks, activates the plugin, and seeds realistic clinic/doctor/patient data via a PHP script. This lab includes known local endpoints and test credentials, making it easy to validate the exploit against localhost:8080. The seed.php file creates WordPress users, populates KiviCare-related metadata, and inserts clinic mappings into KiviCare database tables. Overall, the repository’s purpose is to demonstrate and validate an unauthenticated web authentication bypass and session leakage issue in KiviCare, not merely detect it.
This repository is a real Python proof-of-concept exploit for CVE-2026-2991 affecting the KiviCare Clinic & Patient Management System WordPress plugin up to version 4.1.2. The main exploit file is CVE-2026-2991.py, which uses the requests library to interact with a public KiviCare REST API. It first probes /wp-json/kivicare/v1/ to confirm the plugin namespace is reachable, then submits a crafted POST request to /wp-json/kivicare/v1/auth/patient/social-login with a target email, a claimed social provider (google or apple), and a hardcoded fake token. The exploit relies on the vulnerable endpoint not validating the supplied social token. Primary capability: if the supplied email belongs to a patient account, the script obtains an authenticated session without credentials, prints returned user metadata such as user_id, username, email, roles, nonce, and redirect_url, and extracts WordPress auth cookies from the session. Secondary capability: if the email belongs to a non-patient account such as an administrator, the endpoint may return HTTP 403 after role checking, but the script detects that auth cookies were already issued and prints them for replay. It also generates a browser-console JavaScript snippet that sets document.cookie values and redirects the browser to the returned dashboard URL or /wp-admin/. Repository structure is small and straightforward: one main Python exploit, documentation files, requirements.txt, and a Docker lab under docker/. The Docker lab is not part of the exploit itself but provides a reproducible vulnerable environment. docker-compose.yml launches MySQL and WordPress; Dockerfile installs WordPress, WP-CLI, and the vulnerable KiviCare plugin; entrypoint.sh initializes WordPress files and plugin placement; setup.sh installs WordPress, enables permalinks, activates the plugin, and runs seed.php; seed.php creates a clinic plus seeded admin, doctor, and patient accounts for testing. Overall, the repository’s purpose is to demonstrate and reproduce unauthenticated account takeover of patient users and session leakage for higher-privileged users via the KiviCare social-login REST endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.