A critical security vulnerability, tracked as CVE-2025-6388, has been identified in the Spirit Framework plugin for WordPress, affecting all versions up to and including 1.2.14. The flaw is rooted in the custom_actions() function, which fails to properly validate user identities before authenticating them to the site. This oversight allows unauthenticated attackers to log in as any user, including administrators, provided they know the target username. The vulnerability has been assigned a CVSS score of 9.8, indicating its severe risk level. Security provider Wordfence has confirmed that this vulnerability is being actively exploited in the wild, having blocked 20 attack attempts within a 24-hour period. Attackers leveraging this flaw can bypass standard authentication mechanisms, seize control of user accounts, escalate privileges to administrator, and potentially install backdoors or inject malicious content. The widespread use of WordPress for enterprise, e-commerce, and personal websites amplifies the potential impact of this vulnerability. The Spirit Framework plugin is popular among WordPress site administrators, increasing the number of potentially affected sites. The developers have responded by releasing version 1.2.15 of the plugin, which patches the authentication bypass by ensuring proper identity validation. Website administrators are strongly urged to update to the latest version immediately to mitigate the risk of account takeover and privilege escalation. Failure to apply the patch leaves sites exposed to full compromise, including the risk of data theft, defacement, or further malware deployment. The vulnerability does not require knowledge of a password, only the username of a valid account, making exploitation relatively straightforward for attackers. The incident underscores the importance of prompt patch management and the risks associated with third-party plugins in widely used content management systems. Security advisories have been issued to alert the community, and monitoring for signs of compromise is recommended for sites running affected versions. The rapid exploitation observed highlights the need for continuous vigilance and timely response to critical vulnerabilities in the WordPress ecosystem. Organizations should review their plugin inventories and ensure all components are up to date to prevent similar incidents. The disclosure and patch release demonstrate effective collaboration between security researchers, vendors, and the broader WordPress community in addressing high-impact threats.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
The plugin vendor released Spirit Framework version 1.2.15 to fix the authentication bypass issue. Administrators were urged to update immediately to prevent takeover, defacement, malware deployment, and data theft.
Wordfence reported blocking 20 attack attempts targeting CVE-2025-6388 within a 24-hour period, indicating the vulnerability was being exploited in the wild. Successful exploitation could lead to account takeover, privilege escalation, and full site compromise.
A critical authentication bypass vulnerability, tracked as CVE-2025-6388, was identified in the Spirit Framework WordPress plugin. The flaw affects all versions up to and including 1.2.14 and allows login without the correct password if an attacker knows a valid username.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.