ZeroHour

CVE-2023-2627

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p16
Published
()
Modified
Description

The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings

Vendors
iqonic
Products
kivicare
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.