
CVE-2026-78006 The Events Calendar <= 6.17.4 के लिए POC - अनधिकृत PHP ऑब्जेक्ट इंजेक्शन से रिमोट कोड एक्ज़ीक्यूशन
CVE-2026-78006 The Events Calendar <= 6.17.4 के लिए POC - अनऑथेंटिकेटेड PHP ऑब्जेक्ट इंजेक्शन से रिमोट कोड एक्ज़ीक्यूशन तक
#संपर्क किसी भी प्रश्न के लिए telegram : @soldout0O
यदि आपको मेरा काम पसंद है, तो USDT (TRC20): TQBA72kakjCZLnJt8fJYcD7dyQCEpzNtVN के माध्यम से प्रोजेक्ट का समर्थन करने पर विचार करें
WordPress के लिए The Events Calendar में एक अनऑथेंटिकेटेड PHP ऑब्जेक्ट इंजेक्शन भेद्यता है जिसे रिमोट कोड एक्ज़ीक्यूशन तक श्रृंखलाबद्ध किया जा सकता है।
भेद्य कोड पथ में शामिल हैं:
is_safe_widget_instance()enable_rendering_widget_copied()unserialize()do_blocks()दस्तावेज़ीकृत परिस्थितियों के तहत, एक अनऑथेंटिकेटेड हमलावर इवेंट कमेंट के माध्यम से तैयार किया गया ब्लॉक मार्कअप भेज सकता है और कमेंट मॉडरेशन होने से पहले भेद्य डीसेरियलाइज़ेशन पथ तक पहुँच सकता है।
यह भेद्यता इसलिए मौजूद है क्योंकि प्लगइन की विजेट इंस्टेंस के आसपास की सुरक्षा अपर्याप्त है।
भेद्य प्रवाह को इस प्रकार संक्षेपित किया जा सकता है:```text Unauthenticated Comment | v Pending Event Comment | v WordPress Moderation-Hash URL | v Unauthenticated Author Can View Own Pending Comment | v V2 Single-Event Template | v do_blocks() | v Injected Block Markup | v enable_rendering_widget_copied() | v Forged Integrity Attribute | v is_safe_widget_instance() | v PHP Magic Methods / Object Deserialization | v unserialize() | v PHP Object Injection | v Remote Code Execution
---
# प्रभावित प्लगइन
**प्लगइन:** The Events Calendar
**भेद्यता:** अनधिकृत PHP ऑब्जेक्ट इंजेक्शन जो रिमोट कोड
एक्ज़ीक्यूशन की ओर ले जाता है
**प्रभावित संस्करण:** Wordfence सलाह के अनुसार, **6.17.4** तक और उस सहित
सभी संस्करण।
> [!IMPORTANT]
> इस रिपॉज़िटरी के साथ वर्तमान में प्रकाशित शोध PoC स्वयं को आंतरिक रूप से
> `<= 6.17.2` को लक्षित करने वाला बताता है।
>
> ऊपर बताई गई संस्करण सीमा Wordfence सलाह (`<= 6.17.4`) का अनुसरण करती है।
> किसी डिप्लॉयमेंट का परीक्षण करने से पहले विक्रेता सलाह के विरुद्ध सटीक
> भेद्य/ठीक किए गए संस्करण को हमेशा सत्यापित करें।
---
# मूल कारण
भेद्य व्यवहार विजेट सुरक्षा जाँच और PHP के ऑब्जेक्ट डीसेरियलाइज़ेशन
व्यवहार के बीच अंतःक्रिया से संबंधित है।
शामिल प्रमुख फ़ंक्शन हैं:```text
is_safe_widget_instance()
enable_rendering_widget_copied()
सुरक्षा जाँच अपर्याप्त है क्योंकि PHP अपने पार्सिंग/डीसेरिएलाइज़ेशन व्यवहार के दौरान जादुई विधियों को लागू कर सकता है, इससे पहले कि इच्छित सुरक्षा सत्यापन प्रभावी सुरक्षा प्रदान करे।
यह श्रृंखला इस बात पर भी निर्भर करती है कि प्लगइन आपूर्त किए गए विजेट इंस्टेंस के लिए एक वैध इंटीग्रिटी मान उत्पन्न करता है।
इस भेद्यता की सबसे महत्वपूर्ण विशेषताओं में से एक यह है कि हमलावर को किसी मौजूदा WordPress खाते की आवश्यकता नहीं होती है।
हमले का मार्ग इस बात का दुरुपयोग करता है कि WordPress किस प्रकार एक मॉडरेशन-हैश URL के माध्यम से उपयोगकर्ता की अपनी लंबित टिप्पणी को उजागर करता है।
प्रासंगिक शर्तें ये हैं:```text Comments enabled + Comments visible on events + Attacker can submit an event comment + V2 single-event template active
एक टिप्पणी सबमिट करने के बाद, WordPress एक unauthenticated
moderation-hash URL प्रदान कर सकता है जो टिप्पणीकर्ता को अपनी स्वयं की लंबित
टिप्पणी देखने की अनुमति देता है।
यह तैयार किए गए block
markup के लिए एक unauthenticated delivery mechanism बनाता है।
---
# तकनीकी व्याख्या
## 1. टिप्पणी सबमिशन
हमलावर एक event से संबद्ध एक टिप्पणी सबमिट करता है।
टिप्पणी को अनुमोदित होने की आवश्यकता नहीं है।
महत्वपूर्ण गुण यह है कि WordPress moderation-hash mechanism के माध्यम से
टिप्पणी को उजागर कर सकता है।
---
## 2. Moderation-Hash एक्सेस
WordPress टिप्पणीकर्ता को एक URL प्रदान करता है जो टिप्पणीकर्ता को अपनी
स्वयं की लंबित टिप्पणी देखने की अनुमति देता है।
इसका अर्थ है कि हमलावर moderation की प्रतीक्षा किए बिना
vulnerable rendering path तक पहुँच सकता है।
संकल्पनात्मक रूप से:```text
POST Comment
|
v
Pending Comment
|
v
Moderation Hash
|
v
Unauthenticated Access
The Events Calendar का V2 सिंगल-इवेंट टेम्पलेट इवेंट कंटेंट और कमेंट-संबंधित HTML को प्रोसेस करता है।
संबंधित WordPress प्रोसेसिंग पथ अंततः यहाँ पहुँचता है:```text do_blocks()
यह महत्वपूर्ण है क्योंकि रेंडर किए गए कंटेंट में एम्बेडेड ब्लॉक मार्कअप को WordPress ब्लॉक डेटा के रूप में व्याख्यायित किया जाता है।
---
## 4. तैयार किया गया ब्लॉक डेटा
PoC एक लेगेसी-विजेट ब्लॉक का निर्माण करता है जिसमें एक सीरियलाइज़्ड विजेट इंस्टेंस होता है।
शोध कार्यान्वयन ब्लॉक को एक एन्कोडेड सीरियलाइज़्ड इंस्टेंस और एक इंटीग्रिटी एट्रिब्यूट का उपयोग करके बनाता है।
कमज़ोर पथ अंततः इस डेटा को एक विजेट इंस्टेंस के रूप में प्रोसेस करता है।
---
## 5. इंटीग्रिटी बायपास
प्लगइन के `enable_rendering_widget_copied()` व्यवहार का दुरुपयोग हमलावर-नियंत्रित विजेट डेटा के लिए एक वैध इंटीग्रिटी एट्रिब्यूट उत्पन्न करने के लिए किया जा सकता है।
यह दुर्भावनापूर्ण विजेट इंस्टेंस को अपेक्षित इंटीग्रिटी जाँच पास करने और कमज़ोर प्रोसेसिंग पथ तक पहुँचने की अनुमति देता है।
---
## 6. असुरक्षित ऑब्जेक्ट हैंडलिंग
कमज़ोर `is_safe_widget_instance()` सुरक्षा तैयार किए गए विजेट इंस्टेंस के माध्यम से आपूर्त किए गए ऑब्जेक्ट के विरुद्ध अपर्याप्त है।
PHP का ऑब्जेक्ट हैंडलिंग व्यवहार डीसीरियलाइज़ेशन प्रक्रिया के दौरान मैजिक मेथड्स को इनवोक कर सकता है।
परिणाम एक शोषणयोग्य PHP ऑब्जेक्ट इंजेक्शन प्रिमिटिव है।
---
## 7. गैजेट चेन
शोध PoC WordPress / The Events Calendar ऑब्जेक्ट संरचनाओं का निर्माण करता है जो डीसीरियलाइज़ेशन के दौरान कॉल करने योग्य व्यवहार प्रदान करती हैं।
PoC शोध पेलोड के निर्माण के लिए कॉलबैक-उन्मुख ऑब्जेक्ट्स और सीरियलाइज़्ड क्लास संरचनाओं का उपयोग करता है।
---
## 8. कोड एक्ज़ीक्यूशन
अंतिम प्रभाव Remote Code Execution है।
PoC में एक शोध वेबशेल स्टेज और एडमिनिस्ट्रेटर-निर्माण लॉजिक शामिल है।
सुरक्षित कमज़ोरता सत्यापन के लिए, महत्वपूर्ण सुरक्षा सीमा पहले से ही कमज़ोर डीसीरियलाइज़ेशन चेन के सफल निष्पादन द्वारा प्रदर्शित की गई है।
---
# कमज़ोरता गंभीर क्यों है
निम्नलिखित का संयोजन:```text
Unauthenticated
+
Remote
+
PHP Object Injection
+
RCE
एक उच्च-प्रभाव वाला आक्रमण पथ बनाता है।
आक्रमणकर्ता को आवश्यकता नहीं होती:
मुख्य पर्यावरणीय पूर्वापेक्षा यह है कि भेद्य इवेंट/टिप्पणी रेंडरिंग पथ पहुँच योग्य हो।
रिपॉजिटरी में एक Python-आधारित अनुसंधान कार्यान्वयन शामिल है।
अपलोड किया गया PoC मूल अनुसंधान लॉजिक के चारों ओर एक असिंक्रोनस रनर है।
यह उपयोग करता है:```text Python aiohttp rich
कार्यान्वयन चरणबद्ध पेलोड डिलीवरी और सत्यापन के माध्यम से भेद्यता श्रृंखला को अंजाम देता है।
PoC स्रोत अपनी आर्किटेक्चर का वर्णन इस प्रकार करता है:```text
payload building
|
v
stage 1
|
v
verification
|
v
stage 2
शोध कार्यान्वयन में निम्नलिखित के लिए कार्यक्षमता शामिल है:
PoC में Windows और Unix-जैसे वातावरणों के लिए प्लेटफ़ॉर्म-जागरूक जाँचें भी शामिल हैं।
शोध उपकरण का उपयोग किसी व्यक्तिगत अधिकृत WordPress इंस्टॉलेशन के विरुद्ध किया जा सकता है।
संकल्पनात्मक रूप से:```text Single URL | v Target Discovery | v Event Discovery | v Comment Delivery | v Vulnerability Trigger | v Verification
एकल-लक्ष्य वर्कफ़्लो इनके लिए उपयोगी है:
* स्थानीय लैब्स
* स्टेजिंग सिस्टम्स
* CVE पुनरुत्पादन
* विक्रेता परीक्षण
* अधिकृत पेनेट्रेशन परीक्षण
* सुरक्षा अनुसंधान
---
# URL सूची
अतुल्यकालिक रनर URL की एक सूची का भी समर्थन करता है।
इनपुट प्रारूप है:```text
one URL per line
उदाहरण:```text https://lab-wordpress-01.example https://lab-wordpress-02.example https://lab-wordpress-03.example
रिक्त पंक्तियों और टिप्पणियों को अनदेखा किया जा सकता है।
रनर लक्ष्यों को लोड करता है और उन्हें कॉन्फ़िगर किए गए
थ्रेड/कॉन्करेंसी काउंट का उपयोग करके समवर्ती रूप से संसाधित करता है।
---
# समवर्ती प्रसंस्करण
PoC कई लक्ष्यों के समवर्ती प्रसंस्करण का समर्थन करता है।
संकल्पनात्मक रूप से:```text
URL LIST
|
+-----------+-----------+
| | |
v v v
Worker 1 Worker 2 Worker 3
| | |
v v v
Target Target Target
| | |
+-----------+-----------+
|
v
Results
कार्यान्वयन समवर्तीता स्तर को नियंत्रित करने के लिए एक अतुल्यकालिक सेमाफोर का उपयोग करता है।
रनर में डिफ़ॉल्ट रूप से कॉन्फ़िगर की गई समवर्तीता 20 है।
अतुल्यकालिक रनर दो परिणाम फ़ाइलें बना सकता है:```text shells.txt admins.txt
`shells.txt` में खोजे गए अपलोड किए गए shell URL होते हैं।
`admins.txt` में administrator परिणाम जानकारी इस रूप में होती है:```text
url | user | pass
[!WARNING] इन फ़ाइलों में अत्यंत संवेदनशील क्रेडेंशियल और पोस्ट-एक्सप्लॉइटेशन आर्टिफ़ैक्ट्स हो सकते हैं।
जनरेट किए गए परिणाम फ़ाइलों को कभी भी GitHub पर प्रकाशित न करें।
सार्वजनिक भेद्यता अनुसंधान के लिए, इन फ़ाइलों को Git
रिपॉज़िटरी के बाहर रखें और उन्हें .gitignore में जोड़ें।
shells.txt admins.txt
For responsible vulnerability validation:
START
|
v
प्लगइन संस्करण सत्यापित करें
|
v
पूर्वापेक्षाएँ सत्यापित करें
|
v
पुष्टि करें कि टिप्पणियाँ सक्षम हैं
|
v
पुष्टि करें कि इवेंट्स टिप्पणियाँ उजागर करते हैं
|
v
लैब में पुनरुत्पादन करें
|
v
संवेदनशील व्यवहार की पुष्टि करें
|
v
साक्ष्य और लॉग रिकॉर्ड करें
|
v
रोकें / प्रकट करें```
Use the minimum level of interaction required to prove the finding.
---
# Important Prerequisites
The Wordfence advisory identifies the following important condition:
```text
टिप्पणियाँ सक्षम होनी चाहिए
और
टिप्पणियाँ इवेंट्स पर दिखाई देनी चाहिए```
The attack relies on the ability of an unauthenticated commenter to view
their own pending comment through the WordPress moderation-hash URL.
If comments are disabled or the relevant event comment path is not
available, the documented unauthenticated delivery mechanism may not be
reachable.
---
# Platform Considerations
The PoC contains environment-detection functionality.
The research code attempts to identify information such as:
```text
ऑपरेटिंग सिस्टम
वर्तमान निष्पादन उपयोगकर्ता
वर्तमान कार्यशील निर्देशिका
दस्तावेज़ रूट
सर्वर सॉफ़्टवेयर
HTTP होस्ट
PHP जानकारी```
These values are useful for controlled research and understanding the
impact of successful code execution.
---
# Payload Architecture
The serialized payload contains multiple nested PHP objects.
The research implementation builds structures associated with:
```text
Tribe__Utils__Callback
Tribe\Utils\Element_Classes
stdClass```
The serialized structures are then embedded into a WordPress legacy
widget block.
Conceptually:
```text
PHP ऑब्जेक्ट ग्राफ
|
v
सीरियलाइज़्ड ऑब्जेक्ट
|
v
Base64 एन्कोडिंग
|
v
लेगेसी विजेट ब्लॉक
|
v
WordPress do_blocks()
|
v
The Events Calendar
|
v
ऑब्जेक्ट डीसीरियलाइज़ेशन```
---
# Stage 1
The research PoC's first stage is designed to verify that the injected
object graph reaches the intended execution path.
The stage contains multiple controlled callbacks used to determine
whether code execution or environment disclosure occurred.
The implementation includes research checks such as:
```text
वर्तमान कार्यशील निर्देशिका
निष्पादन उपयोगकर्ता
दस्तावेज़ रूट
सर्वर जानकारी
PHP जानकारी```
---
# Stage 2
If the initial stage does not directly establish the required persistent
artifact location, the PoC contains a second-stage mechanism that
attempts alternative locations.
The research implementation specifically considers WordPress upload
locations and document-root-related paths.
---
# Administrator Stage
The PoC also contains administrator creation functionality.
The research implementation can construct a WordPress administrator
through the vulnerable execution path.
This demonstrates that successful exploitation can result in both:
```text
रिमोट कोड एक्ज़ीक्यूशन
+
स्थायी WordPress एडमिनिस्ट्रेटर एक्सेस```
Administrator credentials generated during research should never be
committed to source control.
---
# Webshell Stage
The PoC contains a webshell stage intended for controlled research.
The webshell is packaged as a WordPress plugin ZIP and deployed through
an authenticated WordPress administrator session established by the
chain.
The research implementation uses a secret token to gate shell requests.
> [!CAUTION]
> The webshell is an exploitation artifact.
>
> Use it only in an isolated laboratory or during an explicitly
> authorized penetration test, and remove it immediately after testing.
---
# Verification
Successful vulnerability validation can be based on evidence such as:
```text
Plugin संस्करण
+
Reachable event
+
Comment delivery
+
Moderation-hash rendering
+
Vulnerable widget processing
+
Controlled execution evidence```
For responsible disclosure, collect only the minimum evidence required.
---
# Impact
Successful exploitation may allow an unauthenticated attacker to:
* Execute arbitrary PHP code
* Execute commands in the context of the web server
* Read sensitive application information
* Access environment information
* Modify WordPress files
* Create administrator accounts
* Install malicious plugins
* Establish persistence
* Potentially compromise the underlying server
The ultimate impact depends on the privileges of the PHP process and
the hosting environment.
---
# Detection
Defenders should monitor for unusual activity involving:
* Event comment submissions
* Pending comments followed by moderation-hash access
* Suspicious block markup
* Legacy widget blocks
* Unexpected widget instance data
* Unexpected serialized PHP objects
* PHP execution triggered during event rendering
* Unexpected plugin installations
* New administrator accounts
* Unexpected PHP files
* Suspicious files under `wp-content/uploads/`
A compromise investigation should correlate:
```text
वेब सर्वर लॉग्स
+
WordPress लॉग्स
+
डेटाबेस गतिविधि
+
फ़ाइल अखंडता
+
प्रशासक खाते```
---
# Indicators of Compromise
Potential indicators include:
```text
अनपेक्षित प्रशासक खाते
अनपेक्षित प्लगइन निर्देशिकाएँ
अनपेक्षित PHP फ़ाइलें
wp-content/uploads/ में संदिग्ध फ़ाइलें
अनपेक्षित इवेंट टिप्पणियाँ
असामान्य मॉडरेशन-हैश अनुरोध
अनपेक्षित विजेट-संबंधित अनुरोध
अनपेक्षित PHP निष्पादन```
Because individual indicators can have legitimate explanations, they
should be investigated in context.
---
# Mitigation
The primary mitigation is to update **The Events Calendar** to a fixed
version provided by the vendor.
Until the plugin is updated, defenders should consider:
* Disabling comments where operationally acceptable
* Restricting public event comments
* Monitoring event comment traffic
* Reviewing recently created administrator accounts
* Monitoring plugin installation activity
* Performing file-integrity checks
* Reviewing web-server logs
* Reviewing WordPress logs
If compromise is suspected, treat the system as potentially compromised
rather than merely vulnerable.
---
# Incident Response
If exploitation is suspected:
1. Preserve relevant logs.
2. Identify suspicious requests.
3. Review administrator accounts.
4. Review installed plugins.
5. Inspect recently modified PHP files.
6. Inspect `wp-content/uploads/`.
7. Rotate WordPress credentials.
8. Rotate hosting/server credentials where appropriate.
9. Remove unauthorized persistence.
10. Restore trusted application files when necessary.
11. Upgrade the vulnerable plugin.
12. Continue monitoring for re-entry.
---
# Responsible Disclosure
When reporting this vulnerability or derivative research:
* Clearly identify the affected plugin.
* Include the affected version.
* Include the fixed version when confirmed.
* Explain the unauthenticated attack path.
* Document the required prerequisites.
* Provide reproducible evidence in a controlled environment.
* Avoid publishing victim data.
* Never publish generated administrator credentials.
* Never publish live webshell URLs.
---
# Research Limitations
A vulnerable plugin version alone does not guarantee successful
exploitation.
The attack path can be affected by:
* WordPress configuration
* Comment settings
* Event visibility
* Template configuration
* Security plugins
* Web Application Firewalls
* Reverse proxies
* PHP configuration
* Hosting permissions
* Object caching
* Network filtering
Therefore, version fingerprinting should be treated as an initial
indicator rather than definitive proof of exploitability.
---
# Repository Safety
Do not commit:
```text
shells.txt
admins.txt
वास्तविक लक्ष्य URL
उत्पन्न क्रेडेंशियल
webshell फ़ाइलें
कैप्चर किया गया phpinfo आउटपुट
डेटाबेस डंप
सर्वर वातावरण जानकारी
निजी परीक्षण डेटा```
Use synthetic laboratory targets when creating screenshots,
demonstrations, or documentation.
---
# Recommended Repository Structure
```text
the-events-calendar-poc/
│
├── poc.py
├── README.md
├── LICENSE
├── .gitignore
│
├── screenshots/
│ └── .gitkeep
│
└── docs/
└── research-notes.md```
Keep runtime artifacts outside the repository.
---
# Technical Summary
```text
The Events Calendar
|
v
V2 Single Event Template
|
v
WordPress do_blocks()
|
v
Legacy Widget Block
|
v
Forged Widget Instance
|
v
Valid Integrity Attribute
|
v
is_safe_widget_instance()
|
v
PHP Object Deserialization
|
v
Magic Method Invocation
|
v
PHP Object Injection
|
v
Remote Code Execution```
---
# Severity
**Impact:** Remote Code Execution
**Authentication:** Not required
**Attack Vector:** Remote
**Primary Component:** The Events Calendar
**Primary Vulnerable Functions:**
```text
is_safe_widget_instance()
enable_rendering_widget_copied()```
**Delivery Mechanism:**
```text
इवेंट टिप्पणियाँ
+
WordPress moderation-hash URL
+
V2 इवेंट रेंडरिंग```
---
# Key Takeaway
The important aspect of this vulnerability is not simply that the plugin
uses PHP serialization.
The complete unauthenticated attack path is enabled by the combination
of:
```text
अपर्याप्त विजेट सत्यापन
+
PHP मैजिक-मेथड व्यवहार
+
जाली अखंडता विशेषता
+
do_blocks()
+
सार्वजनिक इवेंट टिप्पणियाँ
+
मॉडरेशन-हैश पहुँच```
This combination creates an unauthenticated path to PHP Object Injection
and Remote Code Execution.
---
# Credits
Vulnerability details and affected-version information:
**Wordfence Threat Intelligence**
Research PoC:
**The Events Calendar PHP Object Injection / RCE research implementation**
---
# References
* Wordfence Threat Intelligence — The Events Calendar PHP Object
Injection / RCE vulnerability
* The Events Calendar
* WordPress Core
* WordPress Comments
* WordPress Block Editor
* WordPress `do_blocks()`
* PHP Object Serialization / Deserialization
---
# Disclaimer
This repository contains security research concerning a remote-code-
execution vulnerability affecting a WordPress plugin.
The PoC is provided for:
* Security research
* Defensive validation
* Authorized penetration testing
* Controlled laboratory reproduction
* Education
Only test systems that you own or have explicit written authorization
to assess.
The authors are not responsible for unauthorized use of this research.
---
# Keywords
```text
CVE-2026-78006
The Events Calendar
The Events Calendar WordPress
The Events Calendar vulnerability
The Events Calendar RCE
The Events Calendar PHP Object Injection
WordPress
CVE-2026-78006 POC
WordPress Security
WordPress Vulnerability
WordPress RCE
PHP Object Injection
PHP Deserialization
Unauthenticated RCE
Remote Code Execution
CVE
WordPress Plugin Security
WordPress Plugin RCE
is_safe_widget_instance
enable_rendering_widget_copied
do_blocks
WordPress comments
moderation hash
legacy-widget
security research
PoC
Proof of Concept
penetration testing```