Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-78159 — Proof-of-concept exploit for CVE-2026-78159, an unauthenticated RCE in The Events Calendar WordPress plugin via the parse_array widget classes sink. | Kitploit
أدوات/GitHubGitHub/abraxas/cve-2026-78159
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRemote Access Tool
GitHubabraxas/cve-2026-78159

CVE-2026-78159

Proof-of-concept exploit for CVE-2026-78159, an unauthenticated RCE in The Events Calendar WordPress plugin via the parse_array widget classes sink.

عرض المستودع
150منذ 9 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Abraxas Labs - CVE-2026-78159

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-78159

CVE-2026-78159

The Events Calendar 6.17.3 - stellarwp

I am @abraxas_null. Loopback lab. The client is CVE-2026-78159-Abraxas-Labs.py.

parse_array is the sink, not an ajax action=. Unauthenticated comment on a tribe_events post plants a wp:legacy-widget block. V2 single-event buffers comments_template() then do_blocks(). is_safe_widget_instance() rejects objects only, so a plain-array payload reaches Element_Classes::parse_array() and invokes string-callable values. idBase is tribe-widget-events-list, not events-list. Patched in 6.17.3.1 (Wordfence also points at 6.17.4.1 for a sibling).

CVECVE-2026-78159 · CVE.org
CWECWE-94
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductThe Events Calendar
Affectedall versions through 6.17.3 (inclusive)
Patched6.17.3.1 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Comments open on events, classic theme. POST a comment, follow the moderation-preview Location, GET that URL. POCWitness78159 in the HTML means call_user_func ran during render. A real callable in the PHP environment is RCE. The lab canary is poc_witness_78159, not system() and not wp_update_user.


How I found it

Wordfence named parse_array. I read Element_Classes, then Template_Bootstrap do_blocks, then the widget service provider. HTTP is POST /wp-comments-post.php then GET the moderation-preview URL.

Harvest comment_post_ID from /event/lab-event/. POST the legacy-widget comment. Follow Location. SUCCESS only if POCWitness78159 appears after that GET.

Wrong turns already in the lab: generic 200 event HTML without the string; stopping at wp-comments-post 200/302 without following Location; comment 409/duplicate without the block; block theme (tec_is_full_site_editor() skips the bootstrap, so do_blocks never sees comment HTML); system() / exec() / password-reset payload.


The lab

Port 8088. TEC 6.17.3. Twenty Twenty-One. showComments=yes, published lab-event, first comments held. mu-plugin canary.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-78159-Abraxas-Labs.py

Witness: Moderation-preview GET body contains POCWitness78159. Generic event HTML without that string is not it. debug.log may also append it.

Ways to lose without learning anything:

  • generic 200 event HTML without POCWitness78159
  • wp-comments-post.php 200/302 without following Location
  • comment 409/duplicate without the block
  • reverse shell / system() / wp_update_user

The fix

Update The Events Calendar to 6.17.3.1 or newer (Wordfence recommends 6.17.4.1 to also cover CVE-2026-78006). Re-run CVE-2026-78159-Abraxas-Labs.py against the patched build: POCWitness78159 must not appear.


References

  • CVE-2026-78159 · NVD

  • CVE-2026-78159 · CVE.org

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Element_Classes.php#L211

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L214

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L279

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/views/v2/components/messages.php#L30

  • plugins.trac.wordpress.org/changeset?reponame=&old=3667866%40the-events-calendar&new=3667866%40the-events-calendar

  • plugins.trac.wordpress.org/changeset?reponame=&old=3667867%40the-events-calendar&new=3667867%40the-events-calendar

  • www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve

  • github.com/advisories/GHSA-9c57-9fxg-8x9j

  • nvd.nist.gov/vuln/detail/CVE-2026-78159

  • Plugin directory: the-events-calendar

  • Trac browser: plugins.trac.wordpress.org/the-events-calendar

  • SVN tags: plugins.svn.wordpress.org/the-events-calendar

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

تنزيل الأداة