
CVE-2026-13610 The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attacke… https://www.cve.org/CVERecord?id=CVE-2026-13610
Post summary
The CVE notes that the KiviCare WordPress plugin (pre‑4.5.2) allows unauthenticated users to assign roles via its registration endpoint, potentially enabling privilege escalation.
