WordPress Plugin Vulnerability Under Active Attack, Allowing Remote Code Execution
A critical remote code execution vulnerability has been identified in the Sneeit Framework WordPress plugin, which is now under active exploitation. Site administrators are advised to update immediately to version 8.4 or later to prevent potential site…
A critical remote code execution vulnerability has been identified in the Sneeit Framework WordPress plugin, which is now under active exploitation. Site administrators are advised to update immediately to version 8.4 or later to prevent potential site compromise.
On June 10, 2025, a remote code execution vulnerability was discovered in the Sneeit Framework, a WordPress plugin with approximately 1,700 active installations. This vulnerability, designated CVE-2025-6389 and rated with a critical CVSS score of 9.8, affects all plugin versions up to and including version 8.3.
The vulnerability is located in the sneeit_articles_pagination_callback() function, which improperly handles user inputs, forwarding them to PHP's call_user_func() without validation. This flaw allows unauthenticated attackers to execute arbitrary PHP functions, potentially compromising the server.
Following public disclosure, attempts to exploit this vulnerability surged, with over 131,000 exploit attempts blocked by the Wordfence Firewall shortly thereafter. Attackers have employed various strategies to exploit this vulnerability, including the creation of new administrative user accounts and execution of system commands to install backdoors.
A critical remote code execution vulnerability has been identified in the Sneeit Framework WordPress plugin, which is now under active exploitation.
The vulnerability is particularly concerning as it is packaged within multiple premium WordPress themes, extending its potential impact beyond the official plugin repository.
WordPress site administrators should update the Sneeit Framework plugin to version 8.4 or later without delay. Failing to do so significantly increases the risk of site compromise, data theft, and unauthorized administrative access.
For enhanced protection, deploying a web application firewall or utilizing security plugins such as Wordfence is recommended to intercept ongoing exploitation attempts.
Early detection and response were available to Wordfence Premium, Care, and Response users from June 23, 2025, with free users receiving updates on July 23, 2025. However, sites without these protective measures remain vulnerable.
The critical nature of this vulnerability necessitates immediate action to secure affected WordPress installations. By updating promptly and implementing additional security measures, site administrators can mitigate the risk of exploitation.
Based on reporting by GBHackers.
