Critical severity9.8NVD Advisory· Published Nov 25, 2025· Updated Jun 17, 2026
CVE-2025-6389
CVE-2025-6389
Description
The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. This is due to the function accepting user input and then passing that through call_user_func(). This makes it possible for unauthenticated attackers to execute code on the server which can be leveraged to inject backdoors or, for example, create new administrative user accounts.
Affected products
2- Range: <=8.3
Patches
Vulnerability mechanics
References
2News mentions
2- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysThe Hacker News · Jul 13, 2026
- Australia warns of global campaign targeting vulnerable CMS platformsBleepingComputer · Jul 11, 2026