CVE-2026-2992Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Technical Details · 2026-03-18: 203-1803-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure2
2026-03-191
General1
Full discourse3 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-2992 - iqonicdesign - KiviCare – Clinic & Patient Management System (EHR) - https://www.redpacketsecurity.com/cve-alert-cve-2026-2992-iqonicdesign-kivicare-clinic-patient-management-system-ehr/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2992 #iqonicdesign #kivicare-clinic-and-patient-management-system-ehr

    Post summary

    The post announces CVE-2026-2992 affecting KiviCare EHR, but does not provide any technical details, PoC, exploit info, or patch guidance.

    0001086
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2992 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicar… https://www.cve.org/CVERecord?id=CVE-2026-2992

    Post summary

    The message announces that the KiviCare WordPress plugin suffers a privilege escalation flaw caused by missing authorization on a JSON endpoint; it does not provide any PoC, exploit, or patch information.

    00000110
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2992 - High The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clin... https://www.thehackerwire.com/vulnerability/CVE-2026-2992/ https://t.co/2waQDPa6jT

    Post summary

    The post announces that CVE-2026-2992 is a Privilege Escalation vulnerability in the KiviCare WordPress plugin, providing technical details but no PoC, exploit code or evidence of active exploitation.

    0000035
    138 followersView on X

Explore more