CVE-2026-2991 | iqonicdesign KiviCare Plugin up to 4.1.2 on WordPress HTTP Response Header patientSocialLogin improper authentication
A vulnerability classified as critical has been found in iqonicdesign KiviCare Plugin up to 4.1.2 on WordPress. Affected by this issue is the function patientSocialLogin of the component HTTP Response Header Handler. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2026-2991. It is possible to initiate the attack remotely. There is no exploit available.