plugin

Kiotvietsync Vulnerabilities

14 known security issues reported for the Kiotvietsync WordPress plugin. Most recent disclosed Nov 5, 2025.

1 critical 6 medium

Running Kiotvietsync on your site? Check whether your installed version is affected.

Scan your site free

KiotViet Sync [kiotvietsync] <= 1.8.5 (unfixed)

unknown

[en] The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make...

Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 5, 2025

CVE-2025-12674 on NVD →

KiotViet Sync [kiotvietsync] <= 1.8.5 (unfixed)

unknown

[en] The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all versions up to, and including, 1.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's co...

Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 5, 2025

CVE-2025-12675 on NVD →

KiotViet Sync [kiotvietsync] <= 1.8.5 (unfixed)

unknown

[en] The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated function. This makes it possible for unauthenticated attackers to create and s...

Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 5, 2025

CVE-2025-12676 on NVD →

KiotViet Sync [kiotvietsync] <= 1.8.5 (unfixed)

unknown

[en] The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_api_route() function in kiotvietsync/includes/public_actions/WebHookAction.php. This makes it possible for unauthenticated attackers to extract the webhook token value...

Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 5, 2025

CVE-2025-12677 on NVD →

KiotViet Sync <= 1.8.5 - Missing Authorization to Authenticated (Subscriber+) Settings Update

medium

The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all versions up to, and including, 1.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's config.

CVSS:
4.3
Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 4, 2025

CVE-2025-12675 on NVD →

KiotViet Sync <= 1.8.5 - Use of Hard-coded Password to Authorization Bypass

medium

The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin using a hardcoded password for authentication in the QueryControllerAdmin::authenticated function. This makes it possible for unauthenticated attackers to create and sync p...

CVSS:
5.3
Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 4, 2025

CVE-2025-12676 on NVD →

KiotViet Sync <= 1.8.5 - Unauthenticated Arbitrary File Upload

critical

The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remot...

CVSS:
9.8
Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 4, 2025

CVE-2025-12674 on NVD →

KiotViet Sync <= 1.8.5 - Unauthenticated Webhook Key Exposure

medium

The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_api_route() function in kiotvietsync/includes/public_actions/WebHookAction.php. This makes it possible for unauthenticated attackers to extract the webhook token value when...

CVSS:
5.3
Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Nov 4, 2025

CVE-2025-12677 on NVD →

KiotViet Sync [kiotvietsync] <= 1.8.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in Kiotviet KiotViet Sync kiotvietsync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiotViet Sync: from n/a through <= 1.8.5.

Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62978 on NVD →

KiotViet Sync <= 1.8.5 - Missing Authorization

medium

The KiotViet Sync plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Oct 20, 2025

CVE-2025-62978 on NVD →

KiotViet Sync [kiotvietsync] <= 1.8.4 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Kiotviet KiotViet Sync allows Stored XSS. This issue affects KiotViet Sync: from n/a through 1.8.4.

Affected:
up to 1.8.4
Fix:
No patched version reported
Disclosed:
Apr 24, 2025

CVE-2025-39381 on NVD →

KiotViet Sync <= 1.8.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The KiotViet Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged reques...

CVSS:
6.1
Affected:
up to 1.8.5
Fix:
No patched version reported
Disclosed:
Apr 18, 2025

CVE-2025-39381 on NVD →

KiotViet Sync [kiotvietsync] <= 1.8.3 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiotviet KiotViet Sync allows SQL Injection. This issue affects KiotViet Sync: from n/a through 1.8.3.

Affected:
up to 1.8.3
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-32573 on NVD →

KiotViet Sync <= 1.8.4 - Authenticated (Subscriber+) SQL Injection

medium

The KiotViet Sync plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
6.5
Affected:
up to 1.8.4
Fixed in:
1.8.5
Disclosed:
Apr 15, 2025

CVE-2025-32573 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database