Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks
A critical remote code execution vulnerability (CVE-2025-6389) in the Sneeit Framework WordPress plugin is being actively exploited. The flaw allows unauthenticated attackers to execute code on the server, potentially creating malicious admin accounts or injecting backdoors. Wordfence has blocked over 131,000 attack attempts since November 24, 2025. Concurrently, a separate attack exploiting an ICTBroadcast vulnerability (CVE-2025-2611) is being used to spread the 'Frost' DDoS botnet. This botnet combines DDoS capabilities with spreader logic, including exploits for fifteen CVEs. The attacks appear to be part of a small, targeted operation, given the limited number of vulnerable internet-exposed systems.
Pulse ID: 69381affff384c7c0e973a8e
Pulse Link: https://otx.alienvault.com/pulse/69381affff384c7c0e973a8e
Pulse Author: AlienVault
Created: 2025-12-09 12:50:07
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #DDoS #DoS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #botnet #AlienVault