CVE-2025-12676 | KiotViet Sync Plugin up to 1.8.5 on WordPress authenticated hard-coded password
A vulnerability was found in KiotViet Sync Plugin up to 1.8.5 on WordPress and classified as problematic. The affected element is the function QueryControllerAdmin::authenticated. Executing manipulation can lead to use of hard-coded password.
This vulnerability is handled as CVE-2025-12676. The attack can be executed remotely. There is not any exploit available.