PT-2025-45094 · WordPress · Kiotviet Sync

Kenneth Dunn

·

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-12676

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions KiotViet Sync plugin for WordPress versions up to and including 1.8.5
Description The KiotViet Sync plugin for WordPress is susceptible to authorization bypass. This is caused by the use of a hardcoded password for authentication within the QueryControllerAdmin::authenticated function. This allows unauthenticated attackers to create and synchronize products.
Recommendations Update the KiotViet Sync plugin to a version newer than 1.8.5.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-12676

Affected Products

Kiotviet Sync