Medium severity5.3NVD Advisory· Published Jun 8, 2024· Updated Apr 23, 2026
CVE-2024-35659
CVE-2024-35659
Description
Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*range: <=3.6.4
- (no CPE)range: <=3.6.6
Patches
Vulnerability mechanics
References
2- patchstack.com/database/vulnerability/kivicare-clinic-management-system/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerabilitynvdThird Party Advisory
- patchstack.com/database/Wordpress/Plugin/kivicare-clinic-management-system/vulnerability/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerabilitynvd
News mentions
0No linked articles in our index yet.