KiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting
Description
The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in KiviCare WordPress plugin before 3.2.1 allows attackers to inject arbitrary web scripts, targeting high-privilege users like administrators.
Vulnerability
The KiviCare WordPress plugin versions prior to 3.2.1 fail to sanitize and escape a parameter before outputting it back in the page. This leads to a Reflected Cross-Site Scripting (XSS) vulnerability. The affected parameter is not disclosed in the advisory, but it is reachable without any special configuration or authentication [1].
Exploitation
An attacker can craft a malicious URL containing the unsanitized parameter and trick a high-privilege user (e.g., administrator) into clicking it. No authentication is required for the attacker, but user interaction is needed, and the target must be logged into the WordPress admin panel. The attack does not require any special network position; it can be executed remotely [1].
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive information. Because the vulnerability can target administrators, a successful attack could result in full site compromise [1].
Mitigation
The issue is fixed in KiviCare version 3.2.1, released on or around 2023-06-05. Users should update immediately. No workarounds are provided for older versions. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WordPress/KiviCaredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- wpscan.com/vulnerability/dc3a841d-a95b-462e-be4b-acaa44e77264mitreexploitvdb-entrytechnical-description
- packetstormsecurity.com/files/174895/WordPress-KiviCare-3.2.0-Cross-Site-Scripting.htmlmitre
News mentions
0No linked articles in our index yet.