PT-2025-45095 · WordPress · Kiotviet Sync

Kenneth Dunn

·

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-12677

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions KiotViet Sync plugin for WordPress versions up to and including 1.8.5
Description The KiotViet Sync plugin for WordPress is susceptible to exposure of sensitive information. Specifically, unauthenticated attackers can extract the webhook token value when it is configured, through the register api route() function located in the kiotvietsync/includes/public actions/WebHookAction.php file.
Recommendations Update the KiotViet Sync plugin to a version newer than 1.8.5.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-12677

Affected Products

Kiotviet Sync