I don't know if it's wrong, but the concept is idiotic. It's practically opening a door for hackers... and then putting glowing, flashing lights and a huge arrow towards it.
Data should be synced on demand, and the client should not be trusted for an uncorrupted version of it.
If your client can in any way change something that ends up on the server without validation, let alone actually being SYNCHRONIZED with the server without validation, you have made a huge mistake and a potential gaping security hole.