Iqonicdesign
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Iqonicdesign product.
RSS Feeds for Iqonicdesign security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Iqonicdesign products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Iqonicdesign Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 13 vulnerabilities in Iqonicdesign with an average score of 7.0 out of ten. Last year, in 2025 Iqonicdesign had 16 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Iqonicdesign in 2026 could surpass last years number. Last year, the average CVE base score was greater by 1.08
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 13 | 7.00 |
| 2025 | 16 | 8.08 |
| 2024 | 4 | 7.18 |
It may take a day or so for new Iqonicdesign vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Iqonicdesign Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-13709 | Sep 09, 2026 |
Stored XSS in Graphina Charts for Elementor (3.1.11) via iq_tree_tree_chart_templateThe Graphina Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2026-15453 | Aug 15, 2026 |
KiviCare WP Plugin 4.5.1 SQLi via searchTerm (auth)The KiviCare Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare custom role with the 'settings_view' permission (e.g., Doctor or Receptionist), meaning standard WordPress subscribers cannot exploit this without a KiviCare-assigned role. |
|
| CVE-2026-15072 | Jul 11, 2026 |
KiviCare WP Plugin <=4.5.0 SQLi via orderby param (admin+ role)The KiviCare Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that the attacker hold at minimum a KiviCare Doctor-level account, or a Receptionist or Clinic Admin role that grants the doctor_session_list capability. |
|
| CVE-2026-15073 | Jul 11, 2026 |
KiviCare WP Plugin <4.5.0 SQLi via orderby Auth AttackThe KiviCare Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Doctor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare Doctor, Receptionist, or Clinic Admin role at minimum, as the vulnerable REST endpoint is restricted to authenticated users with custom plugin-level access. |
|
| CVE-2026-11990 | Jul 10, 2026 |
KiviCare WP Plugin <4.4: Unauth Auth Bypass to Confirm Appointments & Forge PayThe KiviCare Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending appointments as Confirmed and forge an associated completed payment record in wp_kc_payments_appointment_mappings using an attacker-supplied payment ID, bypassing payment entirely. This exploit is achievable on a default installation because the gateway resolution logic returns all registered gateways regardless of admin-enabled status, making the manual (KCPayLater) gateway always selectable. |
|
| CVE-2026-25413 | Mar 25, 2026 |
WPBookit Pro <=1.6.18 Unrestricted Dangerous File Upload (WP)Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18. |
|
| CVE-2026-25414 | Mar 25, 2026 |
WPBookit Pro <=1.6.18: Privilege Escalation via Incorrect Privilege AssignmentIncorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18. |
|
| CVE-2026-2992 | Mar 18, 2026 |
KiviCare WP Plugin 4.1.2 PrivEsc via /wp-json/kivicare/v1/setup-wizard/clinicThe KiviCare Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges. |
|
| CVE-2026-2991 | Mar 18, 2026 |
KiviCare WP Plugin Auth Bypass <4.1.2 (cve-2026-2991)The KiviCare Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for unauthenticated attackers to log in as any patient registered on the system by providing only their email address and an arbitrary value for the access token, bypassing all credential verification. The attacker gains access to sensitive medical records, appointments, prescriptions, and billing information (PII/PHI breach). Additionally, authentication cookies are set before the role check, meaning the auth cookies for non-patient users (including administrators) are also set in the HTTP response headers, even though a 403 response is returned. |
|
| CVE-2026-1980 | Mar 04, 2026 |
WPBookit <1.0.8: Unauthorized Data Disclosure via get_customer_listThe WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender. |
|