
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2991 is an authentication bypass vulnerability in the KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress, affecting all versions up to and including 4.1.2. The flaw resides in the patientSocialLogin() function, which fails to verify the social provider access token before authenticating a user, allowing unauthenticated attackers to log in as any registered patient using only their email address and an arbitrary token value. It was published on March 18, 2026, and carries a CVSS v3.1 base score of 7.3 (High) (Feedly, Red Hat CVE).
The root cause is classified as CWE-287 (Improper Authentication): the patientSocialLogin() function trusts the caller-supplied access token without performing server-side validation against the social identity provider (Feedly). An attacker sends a crafted network request supplying a known patient email address and any arbitrary string as the access token, and the plugin authenticates the session without verifying the token's authenticity or validity. A secondary design flaw compounds the issue: authentication cookies are set in HTTP response headers before the role check is performed, meaning that even when a non-patient user (including administrators) triggers a 403 response, their authentication cookies are still present in the response headers and can be harvested by the attacker (Feedly). No special privileges or user interaction are required, and exploitation is achievable remotely over the network with low attack complexity.
Successful exploitation allows an unauthenticated attacker to assume the identity of any patient registered in the KiviCare system, gaining access to sensitive medical records, appointments, prescriptions, and billing information — constituting a significant PII/PHI breach with potential HIPAA implications (Feedly). The secondary cookie-leakage flaw means that administrator-level authentication cookies may be exposed in HTTP response headers even when the 403 status code is returned, potentially enabling full administrative account takeover and broader site compromise (Feedly). The combined impact spans confidentiality (medical record exposure), integrity (unauthorized data modification), and availability (disruption of clinic operations).
A high-confidence, fully functional Python proof-of-concept exploit is publicly available on GitHub (PoC GitHub), added on March 18, 2026, and updated through June 2026. The PoC supports patient account takeover and admin session cookie harvesting against live targets, and includes a Docker lab environment for testing. The EPSS score is approximately 0.0019 (0.19%), indicating a currently low but non-negligible probability of exploitation in the wild; no confirmed in-the-wild exploitation or CISA KEV listing has been reported as of the available data (Feedly). The vulnerability is detectable by Qualys (detection ID 531261) (Feedly).
inurl:wp-content/plugins/kivicare-clinic-management-system).patientSocialLogin()), supplying the target patient's email and an arbitrary string as the access_token parameter.python3 CVE-2026-2991.py --url <TARGET_URL> --email <TARGET_EMAIL>) to automate steps 3–6 against the target (PoC GitHub).patientSocialLogin) with arbitrary or malformed access_token values; high volume of login attempts against the social login endpoint from a single IP.Set-Cookie headers in the response.Update the KiviCare plugin to a version newer than 4.1.2, which addresses the authentication bypass (Feedly, Wordfence). As an interim workaround, disable the social login functionality within the plugin settings until patching is complete. Implement server-side validation of social provider access tokens (e.g., verifying tokens against the respective OAuth provider's token introspection endpoint) and ensure authentication cookies are only set after successful role verification. Review server logs for signs of exploitation and consider blocking access to the social login endpoint at the WAF or network perimeter level if the feature is not in use.
Wordfence included CVE-2026-2991 in its weekly WordPress vulnerability report for the week of March 16–22, 2026, highlighting it as a notable authentication bypass affecting a healthcare-focused plugin (Wordfence). The vulnerability received coverage from security aggregators including CVEFeed, VulDB, and the ENISA European Vulnerability Database (EUVD-2026-12838), reflecting broad community awareness. A PoC week roundup published on March 30, 2026, also highlighted the availability of the public exploit (PoC Week).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."