{"id":"CVE-2026-13613","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-13613","summary":"The KiviCare  WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic…","details":"The KiviCare  WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.","published":"2026-08-12T06:17:31.407","modified":"2026-08-12T06:17:31.407","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/76b7d66f-6fa3-41e1-9216-ec125e34ade9/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T06:17:31.407"}}