CVE-2026-78006-CVE-2026-78159
Author
antid00t
Published
2026-09-28
Stars
0
Forks
0
Repository
Description
CVE-2026-78006 + CVE-2026-78159 Mass Exploit
CVE-CVE-2026-78006 Details
Severity
CRITICAL
CVSS Score
9.8
CWE
CWE-502
Description
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execut...
Related PoCs for CVE-2026-78006
CVE-2026-78006-POC...
0
DeadExpl0it