Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2026-78159 — Proof-of-concept exploit for CVE-2026-78159, an unauthenticated RCE in The Events Calendar WordPress plugin via the parse_array widget classes sink. | Kitploit
ツール/GitHubGitHub/abraxas/cve-2026-78159
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRemote Access Tool
GitHubabraxas/cve-2026-78159

CVE-2026-78159

Proof-of-concept exploit for CVE-2026-78159, an unauthenticated RCE in The Events Calendar WordPress plugin via the parse_array widget classes sink.

リポジトリを見る
1509日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

Abraxas Labs - CVE-2026-78159

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-78159

CVE-2026-78159

The Events Calendar 6.17.3 - stellarwp

I am @abraxas_null. Loopback lab. The client is CVE-2026-78159-Abraxas-Labs.py.

parse_array is the sink, not an ajax action=. Unauthenticated comment on a tribe_events post plants a wp:legacy-widget block. V2 single-event buffers comments_template() then do_blocks(). is_safe_widget_instance() rejects objects only, so a plain-array payload reaches Element_Classes::parse_array() and invokes string-callable values. idBase is tribe-widget-events-list, not events-list. Patched in 6.17.3.1 (Wordfence also points at 6.17.4.1 for a sibling).

CVECVE-2026-78159 · CVE.org
CWECWE-94
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductThe Events Calendar
Affectedall versions through 6.17.3 (inclusive)
Patched6.17.3.1 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Comments open on events, classic theme. POST a comment, follow the moderation-preview Location, GET that URL. POCWitness78159 in the HTML means call_user_func ran during render. A real callable in the PHP environment is RCE. The lab canary is poc_witness_78159, not system() and not wp_update_user.


How I found it

Wordfence named parse_array. I read Element_Classes, then Template_Bootstrap do_blocks, then the widget service provider. HTTP is POST /wp-comments-post.php then GET the moderation-preview URL.

Harvest comment_post_ID from /event/lab-event/. POST the legacy-widget comment. Follow Location. SUCCESS only if POCWitness78159 appears after that GET.

Wrong turns already in the lab: generic 200 event HTML without the string; stopping at wp-comments-post 200/302 without following Location; comment 409/duplicate without the block; block theme (tec_is_full_site_editor() skips the bootstrap, so do_blocks never sees comment HTML); system() / exec() / password-reset payload.


The lab

Port 8088. TEC 6.17.3. Twenty Twenty-One. showComments=yes, published lab-event, first comments held. mu-plugin canary.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-78159-Abraxas-Labs.py

Witness: Moderation-preview GET body contains POCWitness78159. Generic event HTML without that string is not it. debug.log may also append it.

Ways to lose without learning anything:

  • generic 200 event HTML without POCWitness78159
  • wp-comments-post.php 200/302 without following Location
  • comment 409/duplicate without the block
  • reverse shell / system() / wp_update_user

The fix

Update The Events Calendar to 6.17.3.1 or newer (Wordfence recommends 6.17.4.1 to also cover CVE-2026-78006). Re-run CVE-2026-78159-Abraxas-Labs.py against the patched build: POCWitness78159 must not appear.


References

  • CVE-2026-78159 · NVD

  • CVE-2026-78159 · CVE.org

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Element_Classes.php#L211

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L214

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L279

  • plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/views/v2/components/messages.php#L30

  • plugins.trac.wordpress.org/changeset?reponame=&old=3667866%40the-events-calendar&new=3667866%40the-events-calendar

  • plugins.trac.wordpress.org/changeset?reponame=&old=3667867%40the-events-calendar&new=3667867%40the-events-calendar

  • www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve

  • github.com/advisories/GHSA-9c57-9fxg-8x9j

  • nvd.nist.gov/vuln/detail/CVE-2026-78159

  • Plugin directory: the-events-calendar

  • Trac browser: plugins.trac.wordpress.org/the-events-calendar

  • SVN tags: plugins.svn.wordpress.org/the-events-calendar

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

ツールをダウンロード