As of early December 2025, dozens of WordPress websites using the Sneeit Framework plugin are under active attack due to a critical remote code execution vulnerability. The bug, tracked as CVE-2025-6389, has already been exploited in the wild — with tens of thousands of attack attempts blocked within just 24 hours of its public disclosure.

What’s Going On

Security firm Wordfence reports that the CVE-2025-6389 vulnerability affects all Sneeit versions up to, and including, 8.3 — a plugin used by more than 1,700 active WordPress installations.

The flaw resides in the plugin’s sneeit_articles_pagination_callback() function, which improperly passes unsanitized user input into PHP’s call_user_func(). This oversight enables unauthenticated attackers to execute arbitrary PHP functions — such as wp_insert_user() — to create backdoor administrator accounts, upload malicious PHP files, or otherwise hijack the site.

Less than 24 hours after public disclosure on November 24, 2025, Wordfence had already blocked over 131,000 exploit attempts — 15,381 of those in a single day.

Attackers have been observed sending specially crafted HTTP requests to typical WordPress endpoints (e.g., /wp-admin/admin-ajax.php), creating malicious admin users such as “arudikadis” and uploading webshells like “tijtewmg.php” to maintain persistent backdoor access.

Compromised sites reportedly store malicious PHP shells — often named “xL.php,” “Canonical.php,” “.a.php,” or “simple.php” — granting attackers full control over the server: directory scanning, file read/write/delete, ZIP extraction, and more.

Why It Matters

RCE vulnerabilities like CVE-2025-6389 are especially dangerous because they give attackers server-level control — meaning they can deface websites, steal or leak data, send spam, or even pivot deeper into hosting infrastructures. In the case of Sneeit, malicious actors can operate without any user credentials, making automated wide-scale attacks trivial.

Moreover, Sneeit is commonly bundled within WordPress themes — which increases the likelihood that some site owners may be unaware of the underlying plugin and therefore miss critical updates.

What to Do: Immediate Actions & Mitigations

  • Update Immediately: Site owners must upgrade to Sneeit version 8.4 or later, the patched release (rolled out on August 5, 2025).
  • Audit & Hard-Harden: Review user accounts for unknown administrators, inspect file systems for suspicious PHP files (especially in upload or plugin directories), and check web-server logs and access patterns.
  • Temporarily Disable Sneeit: If updating is not immediately feasible, consider disabling or removing the Sneeit plugin until patching is possible.
  • Use Web Application Firewalls (WAFs): Deploy WAF rules to block untrusted POST requests, unusual calls to admin-ajax.php, or attempts to drop PHP files.

Security researchers and site administrators alike are also advising stronger supply-chain hygiene — especially avoiding themes bundled with outdated or rarely maintained plugins, and staying alert with vulnerability advisories

Broader Context: WordPress & Plugin Risk Landscape

This incident adds to a growing list of severe plugin-related vulnerabilities rocking the WordPress ecosystem. As attackers increasingly mechanize their reconnaissance and exploitation processes, a single unpatched plugin can jeopardize an entire website — or even a hosting server — overnight.

According to security tracking services, the Sneeit flaw is not unique. Flaws caused by improper input validation, dangerous PHP function execution, or weak plugin maintenance have repeatedly surfaced in 2025 — making plugin management and timely patching among the most critical tasks for any WordPress administrator

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *