Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-78006-POC — POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution | Kitploit
Tools/GitHubGitHub/deadexpl0it/cve-2026-78006-poc
Defensive ToolsPersistence MechanismsVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration TestingPayload DevelopmentRemote Access Trojan
GitHub
4313820 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
deadexpl0it/cve-2026-78006-poc

CVE-2026-78006-POC

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

View Repository
Share

CVE-2026-78006-POC

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

#CONTACT telegram for any ask : @soldout0O

💙 Support the Project

If you appreciate my work, consider supporting the project via USDT (TRC20): TQBA72kakjCZLnJt8fJYcD7dyQCEpzNtVN

The Events Calendar — Unauthenticated PHP Object Injection to RCE

Security Research PoC

The Events Calendar for WordPress contains an unauthenticated PHP Object Injection vulnerability that can be chained to Remote Code Execution.

The vulnerable code path involves:

  • is_safe_widget_instance()
  • enable_rendering_widget_copied()
  • PHP magic-method handling during object deserialization
  • unserialize()
  • The V2 single-event template
  • do_blocks()
  • WordPress comment moderation-hash functionality

Under the documented conditions, an unauthenticated attacker can deliver crafted block markup through an event comment and reach the vulnerable deserialization path before comment moderation occurs.


Vulnerability Summary

The vulnerability exists because the plugin's protection around widget instances is insufficient.

The vulnerable flow can be summarized as:

Unauthenticated Comment
        |
        v
Pending Event Comment
        |
        v
WordPress Moderation-Hash URL
        |
        v
Unauthenticated Author Can View Own Pending Comment
        |
        v
V2 Single-Event Template
        |
        v
do_blocks()
        |
        v
Injected Block Markup
        |
        v
enable_rendering_widget_copied()
        |
        v
Forged Integrity Attribute
        |
        v
is_safe_widget_instance()
        |
        v
PHP Magic Methods / Object Deserialization
        |
        v
unserialize()
        |
        v
PHP Object Injection
        |
        v
Remote Code Execution

Affected Plugin

Plugin: The Events Calendar

Vulnerability: Unauthenticated PHP Object Injection leading to Remote Code Execution

Affected versions: All versions up to and including 6.17.4, according to the Wordfence advisory.

[!IMPORTANT] The research PoC currently published with this repository identifies itself internally as targeting <= 6.17.2.

The version range stated above follows the Wordfence advisory (<= 6.17.4). Always verify the exact vulnerable/fixed version against the vendor advisory before testing a deployment.


Root Cause

The vulnerable behavior is associated with the interaction between the widget safety check and PHP's object deserialization behavior.

The key functions involved are:

is_safe_widget_instance()
enable_rendering_widget_copied()

The security check is insufficient because PHP can invoke magic methods during its parsing/deserialization behavior before the intended safety validation provides effective protection.

The chain also relies on the plugin generating a valid integrity value for the supplied widget instance.


Why Authentication Is Not Required

One of the most important characteristics of this vulnerability is that the attacker does not need an existing WordPress account.

The attack path abuses the way WordPress exposes a user's own pending comment through a moderation-hash URL.

The relevant conditions are:

Comments enabled
        +
Comments visible on events
        +
Attacker can submit an event comment
        +
V2 single-event template active

After submitting a comment, WordPress can provide an unauthenticated moderation-hash URL that allows the commenter to view their own pending comment.

This creates an unauthenticated delivery mechanism for the crafted block markup.


Technical Explanation

1. Comment Submission

The attacker submits a comment associated with an event.

The comment does not need to be approved.

The important property is that WordPress can expose the comment through the moderation-hash mechanism.


2. Moderation-Hash Access

WordPress provides the commenter with a URL that allows the commenter to view their own pending comment.

This means the attacker can reach the vulnerable rendering path without waiting for moderation.

Conceptually:

POST Comment
     |
     v
Pending Comment
     |
     v
Moderation Hash
     |
     v
Unauthenticated Access

3. Event Rendering

The Events Calendar's V2 single-event template processes the event content and comment-related HTML.

The relevant WordPress processing path eventually reaches:

do_blocks()

This is important because block markup embedded in the rendered content is interpreted as WordPress block data.


4. Crafted Block Data

The PoC constructs a legacy-widget block containing a serialized widget instance.

The research implementation builds the block using an encoded serialized instance and an integrity attribute.

The vulnerable path ultimately processes this data as a widget instance.


5. Integrity Bypass

The plugin's enable_rendering_widget_copied() behavior can be abused to produce a valid integrity attribute for the attacker-controlled widget data.

This allows the malicious widget instance to pass the expected integrity check and reach the vulnerable processing path.


6. Unsafe Object Handling

The vulnerable is_safe_widget_instance() protection is insufficient against the object supplied through the crafted widget instance.

PHP's object handling behavior can invoke magic methods during the deserialization process.

The result is an exploitable PHP Object Injection primitive.


7. Gadget Chain

The research PoC constructs WordPress / The Events Calendar object structures that provide callable behavior during deserialization.

The PoC uses callback-oriented objects and serialized class structures to construct the research payload.


8. Code Execution

The final impact is Remote Code Execution.

The PoC contains a research webshell stage and administrator-creation logic.

For safe vulnerability verification, the important security boundary is already demonstrated by successful execution of the vulnerable deserialization chain.


Why the Vulnerability Is Critical

The combination of:

Unauthenticated
       +
Remote
       +
PHP Object Injection
       +
RCE

creates a high-impact attack path.

An attacker does not need:

  • An administrator account
  • A valid WordPress password
  • Password cracking
  • Existing privileged credentials

The main environmental prerequisite is that the vulnerable event/comment rendering path is reachable.


Research PoC

The repository contains a Python-based research implementation.

The uploaded PoC is an asynchronous runner around the original research logic.

It uses:

Python
aiohttp
rich

The implementation performs the vulnerability chain through staged payload delivery and verification.

The PoC source describes its architecture as:

payload building
        |
        v
stage 1
        |
        v
verification
        |
        v
stage 2

PoC Capabilities

The research implementation includes functionality for:

  • Target processing
  • Event discovery
  • Comment delivery
  • Serialized PHP object construction
  • Widget block construction
  • Vulnerability verification
  • Environment information collection
  • Stage-based payload delivery
  • Administrator creation
  • Webshell deployment
  • Result collection
  • Concurrent processing of multiple URLs

The PoC also contains platform-aware checks for Windows and Unix-like environments.


Single Target

The research tool can be used against an individual authorized WordPress installation.

Conceptually:

Single URL
    |
    v
Target Discovery
    |
    v
Event Discovery
    |
    v
Comment Delivery
    |
    v
Vulnerability Trigger
    |
    v
Verification

A single-target workflow is useful for:

Download Tool