Unauthorized Data Modification in KiotViet Sync Plugin for WordPress
CVE-2025-12675
4.3MEDIUM
What is CVE-2025-12675?
The KiotViet Sync plugin for WordPress is susceptible to unauthorized data alterations due to an absence of proper capability checks in the saveConfig() function. This vulnerability affects all versions up to and including 1.8.5, allowing authenticated attackers, who possess Subscriber-level access or higher, to modify the plugin's configuration settings.
Affected Version(s)
KiotViet Sync * <= 1.8.5