The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.
CVE-2026-19417
NONE
EPSS 0.14%
Updated Aug 19, 2026
WordPress
CVE Details
CVE ID
CVE-2026-19417
Published Date
Aug 19, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
4.0th percentile (higher than 4.0% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory