WordPress RCE Exploit CVE-2025-6389: Active Attacks on Sneeit Framework and ICTBroadcast (2026)

A bold warning about ongoing exploitation of critical vulnerabilities in widely used web platforms—and why proactive defense matters—and here’s what you need to know to stay protected.

Threat actors are actively exploiting a dangerous remote code execution vulnerability in the Sneeit Framework WordPress plugin (CVE-2025-6389) alongside a serious flaw in ICTBroadcast (CVE-2025-2611). These breaches are occurring in separate campaigns, as reported by The Hacker News.

Wordfence reports more than 131,000 attempted intrusions targeting the Sneeit vulnerability since November 24. The attackers deploy malicious PHP files and use techniques such as directory scanning, file reading, editing, deletion, and ZIP extraction to gain control, with most activity traced to seven IP addresses. These attempts can enable illicit admin account creation and eventual site takeovers.

Separately, VulnCheck describes campaigns leveraging the ICTBroadcast weakness to deliver Frost, a distributed denial-of-service botnet, to honeypots. The researchers note that the attacker does not simply blast targets; Frost first evaluates specific indicators and only proceeds if the expected conditions are met. This shows a deliberate, targeted approach rather than indiscriminate mass exploitation.

In related industry updates, Barts Health NHS Trust in the UK disclosed a breach tied to the broader Oracle E-Business Suite incident, with data exfiltration reported in August as part of wider activity from the Clop operation. This underscores how even large organizations remain vulnerable to supply-chain and ERP-related intrusions.

Additionally, a wave of vulnerabilities has been found in AI-powered coding tools and IDE extensions. The Hacker News reports more than 30 flaws—collectively dubbed "IDEsaster"—that could allow remote code execution and data compromise in environments like GitHub Copilot, Cursor, Junie, and Windsurf.

For practitioners and organizations, these findings highlight the importance of robust vulnerability management and patch/configuration management practices to reduce exposure and speed remediation.

Discussion prompts: Do you view these targeted exploits as a broader trend toward supply-chain weaknesses, or as isolated incidents tied to specific products? How should organizations balance rapid patch adoption with potential downtime or compatibility concerns? Share your thoughts and experiences in the comments.

WordPress RCE Exploit CVE-2025-6389: Active Attacks on Sneeit Framework and ICTBroadcast (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Greg Kuvalis

Last Updated:

Views: 5748

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Greg Kuvalis

Birthday: 1996-12-20

Address: 53157 Trantow Inlet, Townemouth, FL 92564-0267

Phone: +68218650356656

Job: IT Representative

Hobby: Knitting, Amateur radio, Skiing, Running, Mountain biking, Slacklining, Electronics

Introduction: My name is Greg Kuvalis, I am a witty, spotless, beautiful, charming, delightful, thankful, beautiful person who loves writing and wants to share my knowledge and understanding with you.