Vulnerability Description
The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iqonic | Kivicare | < 3.2.1 |
References
- https://wpscan.com/vulnerability/162d0029-2adc-4925-9985-1d5d672dbe75ExploitThird Party Advisory
- https://wpscan.com/vulnerability/162d0029-2adc-4925-9985-1d5d672dbe75ExploitThird Party Advisory
FAQ
What is CVE-2023-2627?
CVE-2023-2627 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks includ...
How severe is CVE-2023-2627?
CVE-2023-2627 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2627?
Check the references section above for vendor advisories and patch information. Affected products include: Iqonic Kivicare.