logo

Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code

ID: d5a1ac15-051c-5573-bae3-d257190b241e

STIX ID: report--d5a1ac15-051c-5573-bae3-d257190b241e

Feed Name: cybersecurityNews.com

Threat Score
86/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical unauthenticated RCE (CVE-2025-6389, CVSS 9.8) in the Sneeit Framework (versions 8.3 and earlier) is being actively exploited via specially crafted AJAX POST requests to wp-admin/admin-ajax.php, enabling attackers to execute PHP, create admin accounts, upload webshells (examples: xL.php, upsf.php) from domains such as racoonlab.top, and install persistent backdoors; Wordfence reports 131,000+ blocked attempts and recommends immediate update to version 8.4 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.