All verified exploits

CVE-2026-2991 Patient Account Takeover via KiviCare Social Login Bypass

Deterministic critical WordPress Added cve-verified-cve-2026-2991

Detects KiviCare Clinic & Patient Management System plugin versions through 4.1.2 where the social login endpoint accepts any arbitrary string as an OAuth token without verifying it against Google or Apple. An unauthenticated attacker can take over any patient account by providing just their email address. For admin and doctor accounts, valid WordPress session cookies are leaked in the 403 response headers because wp_set_auth_cookie() is called before the role check.

Related WordPress exploits

Is your app exploitable through CVE-2026-2991?

Scan your domain free