CVE-2026-78006 The Events Calendar <= 6.17.4 的 POC - 未认证的 PHP 对象注入导致远程代码执行
CVE-2026-78006 的 POC The Events Calendar <= 6.17.4 - 未认证的 PHP 对象注入导致远程代码执行
#联系方式 telegram 如有任何问题:@soldout0O
如果您欣赏我的工作,请考虑通过 USDT (TRC20): TQBA72kakjCZLnJt8fJYcD7dyQCEpzNtVN 支持本项目
WordPress 的 The Events Calendar 包含一个未认证的 PHP 对象注入漏洞,可被串联利用以实现远程代码 执行。
存在漏洞的代码路径涉及:
is_safe_widget_instance()enable_rendering_widget_copied()unserialize()do_blocks()在所述条件下,未认证的攻击者可以通过事件评论传递 精心构造的区块标记,并在评论审核发生之前 到达存在漏洞的反序列化路径。
该漏洞的存在是因为插件对小工具 实例的保护不足。
存在漏洞的流程可概括为:```text Unauthenticated Comment | v Pending Event Comment | v WordPress Moderation-Hash URL | v Unauthenticated Author Can View Own Pending Comment | v V2 Single-Event Template | v do_blocks() | v Injected Block Markup | v enable_rendering_widget_copied() | v Forged Integrity Attribute | v is_safe_widget_instance() | v PHP Magic Methods / Object Deserialization | v unserialize() | v PHP Object Injection | v Remote Code Execution
---
# 受影响的插件
**插件:** The Events Calendar
**漏洞:** 未认证的 PHP 对象注入导致
远程代码执行
**受影响版本:** 根据 Wordfence 公告,所有版本直至并包括 **6.17.4**。
> [!IMPORTANT]
> 当前随此仓库发布的研究 PoC 内部标识为针对 `<= 6.17.2`。
>
> 上述版本范围遵循 Wordfence 公告
> (`<= 6.17.4`)。在测试部署之前,请始终对照
> 供应商公告核实确切的受影响/修复版本。
---
# 根本原因
该易受攻击的行为与
小部件安全检查及 PHP 对象反序列化行为之间的交互有关。
涉及的关键函数包括:```text
is_safe_widget_instance()
enable_rendering_widget_copied()
安全检查不足,因为 PHP 可以在其解析/反序列化行为期间调用魔术方法,而此时预期的安全验证尚未提供有效保护。
该利用链还依赖于插件为所提供的 widget 实例生成有效的完整性值。
此漏洞最重要的特征之一是攻击者不需要现有的 WordPress 账户。
攻击路径滥用了 WordPress 通过审核哈希 URL 暴露用户自己的待审核评论的方式。
相关条件如下:```text Comments enabled + Comments visible on events + Attacker can submit an event comment + V2 single-event template active
提交评论后,WordPress 可以提供一个未认证的
moderation-hash URL,允许评论者查看自己待审核的
评论。
这为精心构造的区块标记创建了一个未认证的投递机制。
---
# 技术说明
## 1. 评论提交
攻击者提交一条与事件关联的评论。
该评论无需被批准。
关键特性在于 WordPress 可以通过
moderation-hash 机制暴露该评论。
---
## 2. Moderation-Hash 访问
WordPress 向评论者提供一个 URL,允许评论者
查看自己待审核的评论。
这意味着攻击者无需等待审核即可
到达存在漏洞的渲染路径。
概念上:```text
POST Comment
|
v
Pending Comment
|
v
Moderation Hash
|
v
Unauthenticated Access
The Events Calendar 的 V2 单事件模板处理事件 内容及评论相关的 HTML。
相关的 WordPress 处理路径最终到达:```text do_blocks()
这一点很重要,因为嵌入在渲染内容中的区块标记会被解释为 WordPress 区块数据。
---
## 4. 构造的区块数据
PoC 构造了一个包含序列化小工具实例的旧式小工具区块。
研究实现使用编码后的序列化实例和完整性属性来构建该区块。
易受攻击的路径最终将此数据作为小工具实例进行处理。
---
## 5. 完整性绕过
该插件的 `enable_rendering_widget_copied()` 行为可被滥用,从而为攻击者控制的小工具数据生成有效的完整性属性。
这使得恶意小工具实例能够通过预期的完整性检查,并到达易受攻击的处理路径。
---
## 6. 不安全的对象处理
易受攻击的 `is_safe_widget_instance()` 保护不足以抵御通过构造的小工具实例所提供的对象。
PHP 的对象处理行为可在反序列化过程中调用魔术方法。
其结果是可利用的 PHP 对象注入原语。
---
## 7. 利用链
研究 PoC 构造了 WordPress / The Events Calendar 对象结构,这些结构在反序列化期间提供可调用行为。
PoC 使用面向回调的对象和序列化类结构来构造研究载荷。
---
## 8. 代码执行
最终影响是远程代码执行。
PoC 包含一个研究用 webshell 阶段和创建管理员的逻辑。
为了安全地验证漏洞,重要的安全边界已通过成功执行易受攻击的反序列化链得到证明。
---
# 为什么该漏洞至关重要
以下因素的结合:```text
Unauthenticated
+
Remote
+
PHP Object Injection
+
RCE
创建了一条高影响的攻击路径。
攻击者不需要:
主要的环境前提是存在可达的易受攻击的事件/评论渲染路径。
该仓库包含一个基于 Python 的研究实现。
上传的 PoC 是围绕原始研究逻辑的异步运行器。
它使用:```text Python aiohttp rich
该实现通过分阶段载荷投递与验证来执行漏洞利用链。
PoC 源码对其架构的描述如下:```text
payload building
|
v
stage 1
|
v
verification
|
v
stage 2
该研究实现包含以下功能:
该 PoC 还包含针对 Windows 和类 Unix 环境的平台感知检查。
该研究工具可用于单个已授权的 WordPress 安装。
概念上:```text Single URL | v Target Discovery | v Event Discovery | v Comment Delivery | v Vulnerability Trigger | v Verification
单目标工作流适用于:
* 本地实验环境
* 预发布系统
* CVE 复现
* 供应商测试
* 授权渗透测试
* 安全研究
---
# URL 列表
异步运行器还支持 URL 列表。
输入格式为:```text
one URL per line
示例:```text https://lab-wordpress-01.example https://lab-wordpress-02.example https://lab-wordpress-03.example
空行和注释可以被忽略。
运行器加载目标,并使用配置的线程/并发数并发处理它们。
---
# 并发处理
该 PoC 支持对多个目标进行并发处理。
概念上:```text
URL LIST
|
+-----------+-----------+
| | |
v v v
Worker 1 Worker 2 Worker 3
| | |
v v v
Target Target Target
| | |
+-----------+-----------+
|
v
Results
实现使用异步信号量来控制并发级别。
运行器中默认配置的并发数为 20。
异步运行器可以创建两个结果文件:```text shells.txt admins.txt
`shells.txt` 包含已发现的上传 shell URL。
`admins.txt` 包含管理员结果信息,格式如下:```text
url | user | pass
[!WARNING] 这些文件可能包含极其敏感的凭据和 后渗透利用痕迹。
切勿将生成的结果文件发布到 GitHub。
对于公开漏洞研究,请将这些文件保留在 Git
仓库之外,并将其添加到 .gitignore。
shells.txt admins.txt
For responsible vulnerability validation:
START
|
v
验证插件版本
|
v
验证前置条件
|
v
确认评论功能已启用
|
v
确认事件会暴露评论
|
v
在实验环境中复现
|
v
确认存在漏洞行为
|
v
记录证据和日志
|
v
停止 / 披露```
Use the minimum level of interaction required to prove the finding.
---
# Important Prerequisites
The Wordfence advisory identifies the following important condition:
```text
必须启用评论
并且
评论必须在事件上可见```
The attack relies on the ability of an unauthenticated commenter to view
their own pending comment through the WordPress moderation-hash URL.
If comments are disabled or the relevant event comment path is not
available, the documented unauthenticated delivery mechanism may not be
reachable.
---
# Platform Considerations
The PoC contains environment-detection functionality.
The research code attempts to identify information such as:
```text
操作系统
当前执行用户
当前工作目录
文档根目录
服务器软件
HTTP 主机
PHP 信息```
These values are useful for controlled research and understanding the
impact of successful code execution.
---
# Payload Architecture
The serialized payload contains multiple nested PHP objects.
The research implementation builds structures associated with:
```text
Tribe__Utils__Callback
Tribe\Utils\Element_Classes
stdClass```
The serialized structures are then embedded into a WordPress legacy
widget block.
Conceptually:
```text
PHP 对象图
|
v
序列化对象
|
v
Base64 编码
|
v
旧版小工具区块
|
v
WordPress do_blocks()
|
v
The Events Calendar
|
v
对象反序列化```
---
# Stage 1
The research PoC's first stage is designed to verify that the injected
object graph reaches the intended execution path.
The stage contains multiple controlled callbacks used to determine
whether code execution or environment disclosure occurred.
The implementation includes research checks such as:
```text
当前工作目录
执行用户
文档根目录
服务器信息
PHP 信息```
---
# Stage 2
If the initial stage does not directly establish the required persistent
artifact location, the PoC contains a second-stage mechanism that
attempts alternative locations.
The research implementation specifically considers WordPress upload
locations and document-root-related paths.
---
# Administrator Stage
The PoC also contains administrator creation functionality.
The research implementation can construct a WordPress administrator
through the vulnerable execution path.