
Proof-of-concept exploit for CVE-2026-78159, an unauthenticated RCE in The Events Calendar WordPress plugin via the parse_array widget classes sink.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-78159
The Events Calendar 6.17.3 - stellarwp
I am @abraxas_null. Loopback lab. The client is CVE-2026-78159-Abraxas-Labs.py.
parse_array is the sink, not an ajax action=. Unauthenticated comment on a tribe_events post plants a wp:legacy-widget block. V2 single-event buffers comments_template() then do_blocks(). is_safe_widget_instance() rejects objects only, so a plain-array payload reaches Element_Classes::parse_array() and invokes string-callable values. idBase is tribe-widget-events-list, not events-list. Patched in 6.17.3.1 (Wordfence also points at 6.17.4.1 for a sibling).
| CVE | CVE-2026-78159 · CVE.org |
| CWE | CWE-94 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | The Events Calendar |
| Affected | all versions through 6.17.3 (inclusive) |
| Patched | 6.17.3.1 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Comments open on events, classic theme. POST a comment, follow the moderation-preview Location, GET that URL. POCWitness78159 in the HTML means call_user_func ran during render. A real callable in the PHP environment is RCE. The lab canary is poc_witness_78159, not system() and not wp_update_user.
Wordfence named parse_array. I read Element_Classes, then Template_Bootstrap do_blocks, then the widget service provider. HTTP is POST /wp-comments-post.php then GET the moderation-preview URL.
Harvest comment_post_ID from /event/lab-event/. POST the legacy-widget comment. Follow Location. SUCCESS only if POCWitness78159 appears after that GET.
Wrong turns already in the lab: generic 200 event HTML without the string; stopping at wp-comments-post 200/302 without following Location; comment 409/duplicate without the block; block theme (tec_is_full_site_editor() skips the bootstrap, so do_blocks never sees comment HTML); system() / exec() / password-reset payload.
Port 8088. TEC 6.17.3. Twenty Twenty-One. showComments=yes, published lab-event, first comments held. mu-plugin canary.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-78159-Abraxas-Labs.py
Witness: Moderation-preview GET body contains POCWitness78159. Generic event HTML without that string is not it. debug.log may also append it.
Ways to lose without learning anything:
POCWitness78159system() / wp_update_userUpdate The Events Calendar to 6.17.3.1 or newer (Wordfence recommends 6.17.4.1 to also cover CVE-2026-78006). Re-run CVE-2026-78159-Abraxas-Labs.py against the patched build: POCWitness78159 must not appear.
www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve
Plugin directory: the-events-calendar
Trac browser: plugins.trac.wordpress.org/the-events-calendar
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.