HomeSecuritySneeit Framework: Hackers exploit vulnerability in WordPress plugin

Sneeit Framework: Hackers exploit vulnerability in WordPress plugin

A serious security flaw in the WordPress plugin Sneeit Framework has raised alarm among the website administrator community. The vulnerability allows remote code execution, putting thousands of websites worldwide at immediate risk.

Sneeit WordPress Framework

The vulnerability was recorded as CVE-2025-6389 with a CVSS score of 9.8, indicating an extremely high level of risk. The issue affects versions 8.3 and older.

Discovery and public disclosure

Security researchers discovered the flaw on June 10, 2025 , and notified the vendor. The Sneeit Framework development team released an updated version on August 5, 2025, but the vulnerability was only publicly disclosed on November 24, 2025.

See also: Critical vulnerabilities in React and Next.js allow RCE attacks

On the same day of the public disclosure, threat actors launched massive attacks against websites that had not yet installed the update. Wordfence analysts monitored the exploit campaign and recorded that the service’s firewall blocked over 131,000 exploit attempts .

Firewall protection is provided to premium users starting June 23, 2025 , while free users received protection on July 23, 2025. Despite these measures, websites using outdated versions of the add-on continue to be at serious risk.

Vulnerability mechanism

The vulnerability results from insufficient input validation in the sneeitarticlespaginationcallback. The function processes user-supplied parameters without the necessary restrictions, allowing malicious users to send specially crafted AJAX requests to wp-admin/admin-ajax.php and execute arbitrary PHP code on the server.

Sneeit Framework: Hackers exploit vulnerability in WordPress plugin

Attackers exploit the vulnerability via POST requests containing malicious code, often starting with server identification via functions such as phpinfo. They then attempt to create unauthorized administrator accounts or upload malicious PHP files, gaining permanent access to the site.

See also: Serious RCE flaw in OpenAI's Codex CLI highlights new risks

Exploitation methods and malicious tools

A common technique involves using wp_insert_user to create new administrator accounts , giving attackers full control. Alternatively, malicious PHP files with names such as xL.php, Canonical.php, tijtewmg.php are uploaded , which include functions for directory scanning, file management, zip extraction, and permission modification.

One of the most dangerous malware samples is upsf.php, which downloads additional shells from the racoonlab.top. These shells can create .htaccess that bypass restrictions on Apache servers, facilitating further malware distribution.

See also: CISA: Added two Android Framework vulnerabilities to the KEV List

Sneeit Framework: Hackers exploit vulnerability in WordPress plugin

What should administrators do?

WordPress website administrators using the Sneeit Framework should immediately upgrade to version 8.4 or later. This update fixes the critical vulnerability and prevents a complete site compromise and data theft.

Rapid response is essential as threats remain active and attacks continue unabated, exploiting any unpatched installation. Data security and user protection depend on prompt application of the update and the use of a highly reliable firewall.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS