CVE-2026-2991: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2991 is an authentication bypass vulnerability in the KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress, affecting all versions up to and including 4.1.2. The flaw resides in the patientSocialLogin() function, which fails to verify the social provider access token before authenticating a user, allowing unauthenticated attackers to log in as any registered patient using only their email address and an arbitrary token value. It was published on March 18, 2026, and carries a CVSS v3.1 base score of 7.3 (High) (Feedly, Red Hat CVE).

Technical details

The root cause is classified as CWE-287 (Improper Authentication): the patientSocialLogin() function trusts the caller-supplied access token without performing server-side validation against the social identity provider (Feedly). An attacker sends a crafted network request supplying a known patient email address and any arbitrary string as the access token, and the plugin authenticates the session without verifying the token's authenticity or validity. A secondary design flaw compounds the issue: authentication cookies are set in HTTP response headers before the role check is performed, meaning that even when a non-patient user (including administrators) triggers a 403 response, their authentication cookies are still present in the response headers and can be harvested by the attacker (Feedly). No special privileges or user interaction are required, and exploitation is achievable remotely over the network with low attack complexity.

Impact

Successful exploitation allows an unauthenticated attacker to assume the identity of any patient registered in the KiviCare system, gaining access to sensitive medical records, appointments, prescriptions, and billing information — constituting a significant PII/PHI breach with potential HIPAA implications (Feedly). The secondary cookie-leakage flaw means that administrator-level authentication cookies may be exposed in HTTP response headers even when the 403 status code is returned, potentially enabling full administrative account takeover and broader site compromise (Feedly). The combined impact spans confidentiality (medical record exposure), integrity (unauthorized data modification), and availability (disruption of clinic operations).

Exploitability

A high-confidence, fully functional Python proof-of-concept exploit is publicly available on GitHub (PoC GitHub), added on March 18, 2026, and updated through June 2026. The PoC supports patient account takeover and admin session cookie harvesting against live targets, and includes a Docker lab environment for testing. The EPSS score is approximately 0.0019 (0.19%), indicating a currently low but non-negligible probability of exploitation in the wild; no confirmed in-the-wild exploitation or CISA KEV listing has been reported as of the available data (Feedly). The vulnerability is detectable by Qualys (detection ID 531261) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the KiviCare plugin (versions ≤ 4.1.2) using tools like WPScan, Shodan, or Google dorks (e.g., inurl:wp-content/plugins/kivicare-clinic-management-system).
  2. Enumerate patient emails: Obtain a registered patient's email address through open registration pages, appointment booking forms, or other publicly accessible clinic interfaces.
  3. Craft the malicious request: Send a POST request to the KiviCare social login endpoint (e.g., the REST API or AJAX handler invoking patientSocialLogin()), supplying the target patient's email and an arbitrary string as the access_token parameter.
  4. Capture authentication cookies: The server authenticates the session without validating the token and returns authentication cookies in the HTTP response headers. Capture these cookies from the response.
  5. Hijack the patient session: Use the captured cookies to access the patient's dashboard, viewing medical records, prescriptions, appointments, and billing data.
  6. Attempt admin cookie harvest: Repeat the request targeting a known or guessed administrator email. Even if a 403 response is returned, inspect the response headers for authentication cookies that may correspond to the admin account and attempt to reuse them for elevated access.
  7. Automate with PoC: Use the public Python script (python3 CVE-2026-2991.py --url <TARGET_URL> --email <TARGET_EMAIL>) to automate steps 3–6 against the target (PoC GitHub).

Indicators of compromise

  • Network: Unusual POST requests to KiviCare social login endpoints (e.g., WordPress AJAX or REST API routes associated with patientSocialLogin) with arbitrary or malformed access_token values; high volume of login attempts against the social login endpoint from a single IP.
  • Logs: WordPress access logs showing repeated requests to the social login handler with varying email addresses but consistent arbitrary token strings; 403 responses to social login requests that nonetheless set Set-Cookie headers in the response.
  • File System: Unexpected changes to patient records, appointments, or billing data in the WordPress database without corresponding legitimate user activity.
  • Process/Session: Multiple active authenticated sessions for the same patient account from geographically disparate IP addresses; admin sessions initiated shortly after social login 403 responses from the same source IP.

Mitigation and workarounds

Update the KiviCare plugin to a version newer than 4.1.2, which addresses the authentication bypass (Feedly, Wordfence). As an interim workaround, disable the social login functionality within the plugin settings until patching is complete. Implement server-side validation of social provider access tokens (e.g., verifying tokens against the respective OAuth provider's token introspection endpoint) and ensure authentication cookies are only set after successful role verification. Review server logs for signs of exploitation and consider blocking access to the social login endpoint at the WAF or network perimeter level if the feature is not in use.

Community reactions

Wordfence included CVE-2026-2991 in its weekly WordPress vulnerability report for the week of March 16–22, 2026, highlighting it as a notable authentication bypass affecting a healthcare-focused plugin (Wordfence). The vulnerability received coverage from security aggregators including CVEFeed, VulDB, and the ENISA European Vulnerability Database (EUVD-2026-12838), reflecting broad community awareness. A PoC week roundup published on March 30, 2026, also highlighted the availability of the public exploit (PoC Week).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management