CVE-2025-6389Active Exploitation

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. This is due to the function accepting user input and then passing that through call_user_func(). This makes it possible for unauthenticated attackers to execute code on the server which can be leveraged to inject backdoors or, for example, create new administrative user accounts.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-13: 1Mentions · 2026-07-17: 1Mentions · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-03: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-07-17: 1Technical Details · 2026-04-13: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-03: 104-1307-1708-03
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-131
Active Exploitation1
2026-07-171
Active Exploitation1
2026-08-031
General1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    General

    🚨 CVE-2025-6389 - critical 🚨 Sneeit WP Social WordPress Plugin - Unauthenticated RCE via call_user_func > The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in a... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-6389 @pdnuclei #NucleiTem...

    Post summary

    The post announces CVE‑2025‑6389, describing an unauthenticated RCE in the Sneeit WP Social WordPress plugin, and links to a Project DisDiscovery resource, but offers no evidence of active exploitation, a patch, or an exploit tool.

    170213958
    1.3K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    A critical security flaw in the Sneeit Framework plugin for WordPress is being actively exploited in the wild, per data from Wordfence. The remote code execution vulnerability in question is CVE-2025-6389 (CVSS score: 9... https://f.mtr.cool/sqrzpywbvu

    Post summary

    The post reports that CVE-2025-6389, a critical remote code execution flaw in the Sneeit Framework plugin, is being actively exploited in the wild with a CVSS score of 9, but no PoC, patch, or exploit details are provided.

    0000053
    2.1K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-6389 Exploit in the wild confirmed for CVE-2025-6389 (CVSS null). The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all v... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    Active exploitation of CVE-2025-6389 has been confirmed in the wild, targeting the Sneeit Framework WordPress plugin and enabling remote code execution. No patch or mitigation information is provided.

    00000218
    5.6K followersView on X

Explore more