CVE-2025-12675 | KiotViet Sync Plugin up to 1.8.5 on WordPress Setting saveConfig authorization
A vulnerability was found in KiotViet Sync Plugin up to 1.8.5 on WordPress. It has been classified as critical. The impacted element is the function saveConfig of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-12675. The attack is possible to be carried out remotely. No exploit exists.