VYPR
Unrated severityNVD Advisory· Published Jun 27, 2023· Updated Feb 13, 2025

KiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting

CVE-2023-2624

Description

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in KiviCare WordPress plugin before 3.2.1 allows attackers to inject arbitrary web scripts, targeting high-privilege users like administrators.

Vulnerability

The KiviCare WordPress plugin versions prior to 3.2.1 fail to sanitize and escape a parameter before outputting it back in the page. This leads to a Reflected Cross-Site Scripting (XSS) vulnerability. The affected parameter is not disclosed in the advisory, but it is reachable without any special configuration or authentication [1].

Exploitation

An attacker can craft a malicious URL containing the unsanitized parameter and trick a high-privilege user (e.g., administrator) into clicking it. No authentication is required for the attacker, but user interaction is needed, and the target must be logged into the WordPress admin panel. The attack does not require any special network position; it can be executed remotely [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive information. Because the vulnerability can target administrators, a successful attack could result in full site compromise [1].

Mitigation

The issue is fixed in KiviCare version 3.2.1, released on or around 2023-06-05. Users should update immediately. No workarounds are provided for older versions. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.