A vulnerability, which was classified as critical, was found in KiviCare Plugin up to 4.5.1 on WordPress. This affects an unknown function of the component Registration Endpoint. Such manipulation leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2026-13610. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.