
A Windows-friendly, non-destructive Python checker for detecting WordPress installations potentially affected by CVE-2026-14281.
A lightweight, Windows-friendly Python security checker for identifying WordPress installations that may be affected by CVE-2026-14281.
The tool performs passive, non-destructive checks. It does not exploit the vulnerability, create accounts, modify privileges, or alter the target website.
For authorized security testing only. Only scan websites and systems that you own or have explicit permission to assess.
readme.txt| Field | Details |
|---|---|
| CVE | CVE-2026-14281 |
| Product | Automation Web Platform β Notifications and OTP for WooCommerce, Advanced Country Code |
| Affected versions | β€ 4.8.6 |
| Known fixed version | 4.8.7+ |
| Scanner type | Passive / Non-destructive |
The checker uses the detected plugin version to determine whether the installation falls within the known affected version range.
A result of POTENTIALLY VULNERABLE means that the detected version falls within the affected range. It is not a substitute for a full security assessment.
requestscoloramaSupported operating systems:
Clone the repository:
git clone https://github.com/YOUR-USERNAME/CVE-2026-14281-checker.git
cd CVE-2026-14281-checker
Install dependencies:
py -m pip install -r requirements.txt
On Linux/macOS:
python3 -m pip install -r requirements.txt
Windows:
py CVE-2026-14281-check.py https://example.com
Linux/macOS:
python3 CVE-2026-14281-check.py https://example.com
You can also provide a hostname without the scheme:
py CVE-2026-14281-check.py example.com
The checker will normalize it automatically.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β CVE-2026-14281 SAFE CHECKER β
β β
β WordPress Plugin Vulnerability Scanner β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
[*] Checking: https://example.com
[*] Mode: Passive / Non-destructive
Target: https://example.com
HTTP status: 200
WordPress: Detected
Plugin: Detected
Version: 4.8.6
Version source: readme.txt
Confidence: high
CVE status: POTENTIALLY VULNERABLE
Notes:
β’ WordPress indicators detected.
β’ Plugin readme.txt is accessible.
β’ Version 4.8.6 is within the affected range <= 4.8.6.
[!] WARNING: Potentially vulnerable version detected.
[!] Recommended action: update the plugin and investigate the installation.
Change the HTTP timeout:
py CVE-2026-14281-check.py https://example.com --timeout 20
Default:
10 seconds
Useful when inspecting traffic through Burp Suite or another authorized HTTP proxy:
py CVE-2026-14281-check.py https://example.com --proxy http://127.0.0.1:8080
For automation or integration with other security tools:
py CVE-2026-14281-check.py https://example.com --json
Example:
{
"target": "https://example.com",
"reachable": true,
"wordpress_detected": true,
"plugin_detected": true,
"version": "4.8.6",
"version_source": "readme.txt",
"vulnerable": true,
"confidence": "high",
"http_status": 200,
"notes": [
"WordPress indicators detected.",
"Plugin readme.txt is accessible.",
"Version 4.8.6 is within the affected range <= 4.8.6."
]
}
If output is redirected to another program or terminal:
py CVE-2026-14281-check.py https://example.com --no-color
The checker provides useful exit codes for scripting and CI/CD environments.
| Code | Meaning |
|---|---|
0 | Target is not identified as vulnerable |
1 | Potentially vulnerable version detected |
2 | Error or vulnerability status could not be determined |
130 | User interrupted the scan |
Example in Windows:
py CVE-2026-14281-check.py https://example.com
if %ERRORLEVEL% EQU 1 echo Potential vulnerability detected
The checker does not attempt to exploit CVE-2026-14281.
Instead, it performs several passive checks:
The homepage is inspected for common WordPress indicators such as:
wp-contentwp-includeswp-jsonThe response is inspected for references to the affected plugin directory.
The checker attempts to determine the installed version from:
readme.txtIf a version is identified, it is compared against the known affected range.
Version <= 4.8.6
β
βββ YES β Potentially vulnerable
β
βββ NO β Outside known affected range
No passive version checker can guarantee that a target is secure.
Possible limitations include:
readme.txt may be inaccessible.Therefore:
UNKNOWN does not mean secure, and NOT IN AFFECTED VERSION RANGE does not constitute a complete security assessment.
For confirmed remediation, verify the installed plugin directly from the WordPress administration environment or package/filesystem information.
This project intentionally avoids active exploitation.
It does not:
The purpose is vulnerability identification, not exploitation.
CVE-2026-14281-checker/
β
βββ CVE-2026-14281-check.py
βββ requirements.txt
βββ README.md
βββ LICENSE
βββ .gitignore
The project uses:
HTTP client used for communicating with the target.
Provides reliable colored terminal output on Windows.
Install all dependencies with:
pip install -r requirements.txt
If you discover a vulnerable installation that you are authorized to assess:
Do not use this tool to scan systems without authorization.
This project is provided for defensive security research, vulnerability assessment, education, and authorized penetration testing.