A critical security flaw in the Sneeit Framework for WordPress is already being actively exploited, according to data from Wordfence.
See also: King Addons for Elementor: Critical vulnerability in WordPress plugin

This remote code execution (RCE) vulnerability, CVE-2025-6389 (CVSS score: 9.8), affects all versions of the add-on up to and including 8.3. The issue was fixed in version 8.4, released on August 5, 2025. The add-on has over 1,700 active installations.
Simply put, the vulnerability allows any PHP function — such as wp_insert_user() — to be called to create a malicious administrative account. The attacker can then gain full control of the website and inject malicious code that redirects visitors to suspicious pages, malware, or spam.
Wordfence reported that the exploit "in the field" began on November 24, 2025, the same day it was made public, with the company blocking over 131,000 attempts to exploit the vulnerability. Of these, 15,381 attacks were recorded in the last 24 hours.
See also: WordPress: Serious vulnerability in the W3 Total Cache plugin

Part of the attackers ' actions include sending specially crafted HTTP requests to the endpoint “/wp-admin/admin-ajax.php ” , aiming to create a malicious administrator account — such as the user “ arudikadis ” — as well as uploading a malicious PHP file ( “ tijtewmg.php ” ), which likely provides backdoor access .
The attacks come from the following IP addresses:
- 185.125.50[.]59
- 182.8.226[.]51
- 89.187.175[.]80
- 194.104.147[.]192
- 196.251.100[.]39
- 114.10.116[.]226
- 116.234.108[.]143
The WordPress security firm said it also detected malicious PHP files with directory scanning capabilities, as well as the ability to read, modify or delete files and their permissions, and can even decompress ZIP archives. These files appear with names such as “xL.php“, “Canonical.php“, “.a.php“ and “simple.php“.
See also: GootLoader: New hiding technique on WordPress websites

According to Wordfence, the “xL.php“ is taken from another PHP file called “up_sf.php“, which is designed to exploit the vulnerability. This file also downloads a “.htaccess“ from an external server (“racoonlab[.]top“) to the already compromised system.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
