
POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution
POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution
#CONTACT telegram for any ask : @soldout0O
If you appreciate my work, consider supporting the project via USDT (TRC20): TQBA72kakjCZLnJt8fJYcD7dyQCEpzNtVN
The Events Calendar for WordPress contains an unauthenticated PHP Object Injection vulnerability that can be chained to Remote Code Execution.
The vulnerable code path involves:
is_safe_widget_instance()enable_rendering_widget_copied()unserialize()do_blocks()Under the documented conditions, an unauthenticated attacker can deliver crafted block markup through an event comment and reach the vulnerable deserialization path before comment moderation occurs.
The vulnerability exists because the plugin's protection around widget instances is insufficient.
The vulnerable flow can be summarized as:
Unauthenticated Comment
|
v
Pending Event Comment
|
v
WordPress Moderation-Hash URL
|
v
Unauthenticated Author Can View Own Pending Comment
|
v
V2 Single-Event Template
|
v
do_blocks()
|
v
Injected Block Markup
|
v
enable_rendering_widget_copied()
|
v
Forged Integrity Attribute
|
v
is_safe_widget_instance()
|
v
PHP Magic Methods / Object Deserialization
|
v
unserialize()
|
v
PHP Object Injection
|
v
Remote Code Execution
Plugin: The Events Calendar
Vulnerability: Unauthenticated PHP Object Injection leading to Remote Code Execution
Affected versions: All versions up to and including 6.17.4, according to the Wordfence advisory.
[!IMPORTANT] The research PoC currently published with this repository identifies itself internally as targeting
<= 6.17.2.The version range stated above follows the Wordfence advisory (
<= 6.17.4). Always verify the exact vulnerable/fixed version against the vendor advisory before testing a deployment.
The vulnerable behavior is associated with the interaction between the widget safety check and PHP's object deserialization behavior.
The key functions involved are:
is_safe_widget_instance()
enable_rendering_widget_copied()
The security check is insufficient because PHP can invoke magic methods during its parsing/deserialization behavior before the intended safety validation provides effective protection.
The chain also relies on the plugin generating a valid integrity value for the supplied widget instance.
One of the most important characteristics of this vulnerability is that the attacker does not need an existing WordPress account.
The attack path abuses the way WordPress exposes a user's own pending comment through a moderation-hash URL.
The relevant conditions are:
Comments enabled
+
Comments visible on events
+
Attacker can submit an event comment
+
V2 single-event template active
After submitting a comment, WordPress can provide an unauthenticated moderation-hash URL that allows the commenter to view their own pending comment.
This creates an unauthenticated delivery mechanism for the crafted block markup.
The attacker submits a comment associated with an event.
The comment does not need to be approved.
The important property is that WordPress can expose the comment through the moderation-hash mechanism.
WordPress provides the commenter with a URL that allows the commenter to view their own pending comment.
This means the attacker can reach the vulnerable rendering path without waiting for moderation.
Conceptually:
POST Comment
|
v
Pending Comment
|
v
Moderation Hash
|
v
Unauthenticated Access
The Events Calendar's V2 single-event template processes the event content and comment-related HTML.
The relevant WordPress processing path eventually reaches:
do_blocks()
This is important because block markup embedded in the rendered content is interpreted as WordPress block data.
The PoC constructs a legacy-widget block containing a serialized widget instance.
The research implementation builds the block using an encoded serialized instance and an integrity attribute.
The vulnerable path ultimately processes this data as a widget instance.
The plugin's enable_rendering_widget_copied() behavior can be abused
to produce a valid integrity attribute for the attacker-controlled
widget data.
This allows the malicious widget instance to pass the expected integrity check and reach the vulnerable processing path.
The vulnerable is_safe_widget_instance() protection is insufficient
against the object supplied through the crafted widget instance.
PHP's object handling behavior can invoke magic methods during the deserialization process.
The result is an exploitable PHP Object Injection primitive.
The research PoC constructs WordPress / The Events Calendar object structures that provide callable behavior during deserialization.
The PoC uses callback-oriented objects and serialized class structures to construct the research payload.
The final impact is Remote Code Execution.
The PoC contains a research webshell stage and administrator-creation logic.
For safe vulnerability verification, the important security boundary is already demonstrated by successful execution of the vulnerable deserialization chain.
The combination of:
Unauthenticated
+
Remote
+
PHP Object Injection
+
RCE
creates a high-impact attack path.
An attacker does not need:
The main environmental prerequisite is that the vulnerable event/comment rendering path is reachable.
The repository contains a Python-based research implementation.
The uploaded PoC is an asynchronous runner around the original research logic.
It uses:
Python
aiohttp
rich
The implementation performs the vulnerability chain through staged payload delivery and verification.
The PoC source describes its architecture as:
payload building
|
v
stage 1
|
v
verification
|
v
stage 2
The research implementation includes functionality for:
The PoC also contains platform-aware checks for Windows and Unix-like environments.
The research tool can be used against an individual authorized WordPress installation.
Conceptually:
Single URL
|
v
Target Discovery
|
v
Event Discovery
|
v
Comment Delivery
|
v
Vulnerability Trigger
|
v
Verification
A single-target workflow is useful for: