CVE-2026-19417Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-19: 3Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-19: 208-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-19417 KiviCare WordPress Plugin Allows Patient-Level Media File... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19417 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet mentions CVE-2026-19417 and provides links to vulnerability details and scanning alerts, but offers no additional technical or exploit information.

    00000100
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19417 The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level … https://www.cve.org/CVERecord?id=CVE-2026-19417 ----- Traducción: CVE-2026-19417 El … https://infoflow.cloud`

    Post summary

    The KiviCare WordPress plugin is affected by CVE‑2026‑19417, where lack of entitlement checks lets authenticated users access media files they are not authorized to view.

    0000028
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19417 The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level … https://www.cve.org/CVERecord?id=CVE-2026-19417

    Post summary

    The post provides a technical disclosure of a vulnerability in the KiviCare WordPress plugin, noting that versions prior to 4.5.4 lack proper access checks for media files.

    00000566
    58.0K followersView on X

Explore more