CVE-2025-12677 | KiotViet Sync Plugin up to 1.8.5 on WordPress Webhook Token WebHookAction.php register_api_route information disclosure
A vulnerability described as problematic has been identified in KiotViet Sync Plugin up to 1.8.5 on WordPress. Affected by this vulnerability is the function register_api_route of the file kiotvietsync/includes/public_actions/WebHookAction.php of the component Webhook Token Handler. Executing manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2025-12677. It is possible to launch the attack remotely. No exploit is available.