Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2026-78159 — CVE-2026-78159 の概念実証エクスプロイト。The Events Calendar WordPress プラグインにおける、parse_array ウィジェットクラスのシンクを経由した未認証 RCE。 | Kitploit
ツール/GitHubGitHub/abraxas/cve-2026-78159
脆弱性分析エクスプロイトウェブアプリケーション悪用ウェブセキュリティペネトレーションテストリモートアクセスツール
GitHubabraxas/cve-2026-78159

CVE-2026-78159

CVE-2026-78159 の概念実証エクスプロイト。The Events Calendar WordPress プラグインにおける、parse_array ウィジェットクラスのシンクを経由した未認証 RCE。

リポジトリを見る
7時間27分前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Abraxas Labs — CVE-2026-78159

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  CVE-2026-78159

CVE-2026-78159

The Events Calendar 6.17.3 — stellarwp

WordPress 用 The Events Calendar プラグインは、parse_array 関数を介して 6.17.3 以前のすべてのバージョンでリモートコード実行に対して脆弱です。これはウィジェットの 'classes' マップの検証が不十分であるため、プレーン配列のペイロードが is_safe_widget_instance() のオブジェクトチェックをバイパスし、Element_Classes::parse_array() 内の呼び出し可能オブジェクト呼び出しシンクに到達できることに起因します。これにより、認証されていない攻撃者がサーバー上でコードを実行できる可能性があります。悪用には、対象サイトで tribe_events 投稿のコメントが有効になっており、細工された wp:legacy-widget ブロックを含むコメントが少なくとも 1 件投稿されている必要があります。これは、do_blocks() がコメント領域を含む単一イベント HTML を処理するときに攻撃チェーンがトリガーされるためです。

CVECVE-2026-78159 · CVE.org
CWECWE-94
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductThe Events Calendar
Affected6.17.3 までのすべてのバージョン(含む)
Patched6.17.3.1 以降
Authなし(ソースマップを参照)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 のみ · ベンダー/クライアント開示パックであり、スキャナーではありません

アドバイザリ(ソースマップより)

parse_array はシンクであり、ajax action= ではありません。HTTP は POST /wp-comments-post.php の後に GET でモデレーションプレビュー URL です。ウィジェットの idBase は tribe-widget-events-list であり、events-list ではありません。


エントリ

  • Method: POST
  • Path: /wp-comments-post.php
  • Router: 未認証の wp-comments-post.php。TEC V2 単一イベントは comments_template() をバッファリングしてから do_blocks() を実行します。render_block_data は tribe-widget-* インスタンスを再ハッシュします。the_widget('tribe-widget-events-list') を featured_events_only true で呼び出すとリストが空になり、components/messages.php が tec_classes($classes) を実行します。Element_Classes::parse_array は文字列呼び出し可能値を呼び出します。ラボのカナリアは poc_witness_78159 であり、system() でも wp_update_user でもありません。
  • Notes: CVE-2026-78159 CWE-94: The Events Calendar 6.17.3。idBase は tribe-widget-events-list でなければなりません(プレフィックス tribe-widget- + スラッグ events-list)。ダミーハッシュで問題ありません。最初の GET /event/lab-event/ は収集のみです。コメントリダイレクト後に POCWitness78159 が現れた場合のみ SUCCESS です。

呼び出しチェーン

  • GET /event/lab-event/ で comment_post_ID を収集
  • POST /wp-comments-post.php comment=<!-- wp:legacy-widget {idBase tribe-widget-events-list, instance.encoded php-serialize-base64, instance.hash 0} /-->
  • 302 Location に unapproved=COMMENT_ID&moderation-hash=wp_hash(comment_date_gmt) が含まれる
  • その Location を GET: comments_template が未承認コメントを含める
  • Template_Bootstrap::get_v1_single_event_template_html do_blocks($html)
  • Service_Provider::enable_rendering_widget_copied (render_block_data) unserialize allowed_classes false、is_safe_widget_instance はオブジェクトのみを拒否、プレーン配列を wp_hash
  • render_block_core_legacy_widget the_widget tribe-widget-events-list
  • Widget_List setup_arguments array_merge instance(classes は存続、setup_template_vars は上書きしない)
  • 空の featured リスト -> widget-events-list.php の else 分岐 components/messages.php
  • tec_classes($classes) -> Element_Classes::parse_array 文字列キー + is_callable 値 -> poc_witness_78159($results) が POCWitness78159 を出力

ラボの前提条件

  • The Events Calendar 6.17.3 が有効
  • クラシックテーマ(Twenty Twenty-One)。ブロックテーマは tec_is_full_site_editor() を介して Template_Bootstrap::filter_template_include をスキップするため、do_blocks がコメント HTML を認識しません
  • tribe_events_calendar_options showComments=yes で tribe_events がコメントをサポート
  • 公開された tribe_events 投稿 lab-event で comment_status=open
  • comment_registration=0、最初のコメントは保留(unapproved + moderation-hash)
  • mu-plugin 関数 poc_witness_78159 が POCWitness78159 を出力(ラボのカナリアであり、ガジェットチェーンではありません)
  • V2 ビュー/ウィジェットが有効(6.17.3 では常に true)

ウィットネス

モデレーションプレビュー GET の HTTP ボディに POCWitness78159 が含まれます。その文字列を含まない一般的なイベント HTML は該当しません。debug.log にも POCWitness78159 が追記される場合があります。

成功ではないもの

  • POCWitness78159 を含まない一般的な 200 イベント HTML
  • Location をフォローしない wp-comments-post.php の 200/302
  • ブロックを含まないコメントの 409/重複
  • ウィットネスを含まない 403/404
  • リバースシェルまたは外向き接続
  • system()/exec()/wp_update_user のパスワードリセットペイロード

パッチ / 修復

まずこれを実行: The Events Calendar を 6.17.3.1 以降に更新してください(Wordfence は CVE-2026-78006 もカバーするために 6.17.4.1 を推奨しています)。

アップグレード後の確認

  • パッチ適用済みビルドに対して CVE-2026-78159-Abraxas-Labs.py を再実行: マップされたウィットネスが現れないことを確認してください。
  • デプロイされたツリーでベンダーアドバイザリ / チェンジセットを確認してください(参考文献を参照)。
  • WAF シグネチャは遅延であり、パッチではありません。

すぐに更新できない場合

  • 影響を受けるコンポーネントを無効化または隔離してください。
  • 本番環境でウィットネス条件を探してください(新しい特権ユーザー、予期しないファイル、注入された行 — この CVE のマップが示すものは何でも)。

再現(許可されたラボ)

http://127.0.0.1:8088(またはバインドしたループバック)のみを対象にしてください。このスクリプトをインターネットに向けないでください。

root@kitploit:~
python3 CVE-2026-78159-Abraxas-Labs.py

成功とは、レスポンスボディに上記のウィットネスが含まれることです。一般的な 200 HTML は該当しません。


ラボイメージ

再現に使用したループバックスタック。このフォルダ内の Dockerfile がソースからビルドする場合を除き、公式イメージです。

  • lab/docker-compose.yml
  • lab/docker-compose.override.yml
  • lab/Dockerfile
root@kitploit:~
cd lab
docker compose up --force-recreate

YAML がローカルディレクトリをマウントする場合(バージョンテーブルからのプラグイン zip / ソースタグ)、脆弱な製品ツリーを Compose の隣にバインドしてください。127.0.0.1 以外は公開しないでください。


参考文献

  • CVE-2026-78159 · NVD

  • CVE-2026-78159 · CVE.org

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Element_Classes.php#L211

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L214

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L279

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/views/v2/components/messages.php#L30

  • plugins.trac.wordpress.org/changeset?reponame=&old=3667866%40the-events-calendar&new=3667866%40the-events-calendar

  • plugins.trac.wordpress.org/changeset?reponame=&old=3667867%40the-events-calendar&new=3667867%40the-events-calendar

  • www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve

  • github.com/advisories/GHSA-9c57-9fxg-8x9j

  • nvd.nist.gov/vuln/detail/CVE-2026-78159

  • プラグインディレクトリ: the-events-calendar

  • Trac ブラウザ: plugins.trac.wordpress.org/the-events-calendar

  • SVN タグ: plugins.svn.wordpress.org/the-events-calendar

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


レコード(構造化)

root@kitploit:~
# CVE-2026-78159  (structured records)

- input: `https://nvd.nist.gov/vuln/detail/CVE-2026-78159`
- CWE: CWE-94
- published: 2026-09-12T08:16:24.377

## NVD description

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.

## MITRE description

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.

## Affected

- stellarwp The Events Calendar 0 affected

## References (JSON sources only)

- https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Element_Classes.php#L211
- https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L214
- https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L279
- https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/views/v2/components/messages.php#L30
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3667866%40the-events-calendar&new=3667866%40the-events-calendar
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3667867%40the-events-calendar&new=3667867%40the-events-calendar
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve
- https://github.com/advisories/GHSA-9c57-9fxg-8x9j
- https://nvd.nist.gov/vuln/detail/CVE-2026-78159

## GitHub advisory

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all...

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.

ライセンス

この開示パックは GNU Affero General Public License v3.0 の下でライセンスされています。LICENSE を参照してください。


免責事項

このパックはベンダー、サイト所有者、およびライセンスを受けたラボ向けです。スクリプトは 127.0.0.1 と通信します。所有していないシステムに対して使用することは Abraxas Labs によって許可されていません。保証はありません。

abraxaslabs.tech · github.com/abraxas · @abraxas_null

ツールをダウンロード