S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0786 Scanner

CVE-2022-0786 scanner - SQL Injection (SQLi) vulnerability in KiviCare plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0786
9.8
CVSS

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
KiviCare – Clinic & Patient Management System (EHR)
AFFECTED< 2.3.9SAFE ✓≥ 2.3.9
Updated Aug 22, 2026View on NVD →
Detail

The KiviCare plugin for WordPress is a tool designed to provide healthcare professionals with a convenient and efficient way of managing patient information and appointments. It enables doctors and other healthcare workers to organize their schedules, manage billing and invoices, and track patient records in real-time. With the ever-increasing need to streamline medical records and improve patient care, the KiviCare plugin has become increasingly popular among healthcare providers.

However, recent research has uncovered a vulnerability in the KiviCare plugin, identified as CVE-2022-0786. The vulnerability stems from a failure to sanitize and escape certain parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route. This oversight allows unauthenticated users to exploit the plugin and execute SQL injection attacks, leading to the exposure of sensitive patient information and other data stored on the platform. 

If exploited, this vulnerability can lead to a range of problems, including the unauthorized sharing of patient data, the alteration or deletion of records, and the compromise of various system components. These attacks can have disastrous consequences for both patients and healthcare providers alike, leading to legal and ethical violations and compromising the integrity of medical services. 

In conclusion, the KiviCare plugin for WordPress is a useful tool for healthcare professionals, but it is not immune to vulnerabilities. The recent CVE-2022-0786 vulnerability showcased the importance of properly sanitizing and escaping parameters before using them in SQL statements. By taking the proper precautions, healthcare providers can ensure the safety and integrity of their patient records and avoid potential legal and ethical violations. Additionally, s4e.io offers pro features that allow users to quickly and easily identify and mitigate vulnerabilities in their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update to the latest version of the KiviCare plugin
  • Use a web application firewall to monitor for and block SQL injection attempts
  • Implement strong authentication measures, such as two-factor authentication or biometric authentication
  • Review and monitor logs for suspicious activity 
  • Educate employees on good security practices and the risks of SQL injection attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.