Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-14281-check β€” A Windows-friendly, non-destructive Python checker for detecting WordPress installations potentially affected by CVE-2026-14281. | Kitploit
Tools/GitHubGitHub/abatsakidis/cve-2026-14281-check
Defensive ToolsReconnaissanceVulnerability ScannersWeb Vulnerability ScannersVulnerability AnalysisInformation GatheringWeb Security
GitHub

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
abatsakidis/cve-2026-14281-check

CVE-2026-14281-check

A Windows-friendly, non-destructive Python checker for detecting WordPress installations potentially affected by CVE-2026-14281.

View Repository
45 days agoNot yet reviewed
Share

CVE-2026-14281 Checker

A lightweight, Windows-friendly Python security checker for identifying WordPress installations that may be affected by CVE-2026-14281.

The tool performs passive, non-destructive checks. It does not exploit the vulnerability, create accounts, modify privileges, or alter the target website.

For authorized security testing only. Only scan websites and systems that you own or have explicit permission to assess.


Features

  • πŸ”Ž Detects WordPress indicators
  • πŸ”Œ Detects the affected plugin
  • 🏷️ Attempts to identify the installed plugin version
  • πŸ“„ Checks the plugin's public readme.txt
  • πŸ›‘οΈ Determines whether the detected version falls within the known affected range
  • πŸͺŸ Designed to work correctly on Windows CMD and PowerShell
  • 🎨 Windows-compatible colored terminal output using Colorama
  • 🌐 Optional HTTP/HTTPS proxy support
  • πŸ“Š JSON output for automation and CI/CD workflows
  • ⏱️ Configurable HTTP timeout
  • 🚫 No exploit requests
  • 🚫 No account creation
  • 🚫 No privilege modification
  • 🚫 No OTP bypass attempts

CVE Information

FieldDetails
CVECVE-2026-14281
ProductAutomation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
Affected versions≀ 4.8.6
Known fixed version4.8.7+
Scanner typePassive / Non-destructive

The checker uses the detected plugin version to determine whether the installation falls within the known affected version range.

A result of POTENTIALLY VULNERABLE means that the detected version falls within the affected range. It is not a substitute for a full security assessment.


Requirements

  • Python 3.9+
  • Internet/network access to the target
  • requests
  • colorama

Supported operating systems:

  • Windows 10 / 11
  • Linux
  • macOS

Installation

Clone the repository:

git clone https://github.com/YOUR-USERNAME/CVE-2026-14281-checker.git
cd CVE-2026-14281-checker

Install dependencies:

py -m pip install -r requirements.txt

On Linux/macOS:

python3 -m pip install -r requirements.txt

Basic Usage

Windows:

py CVE-2026-14281-check.py https://example.com

Linux/macOS:

python3 CVE-2026-14281-check.py https://example.com

You can also provide a hostname without the scheme:

py CVE-2026-14281-check.py example.com

The checker will normalize it automatically.


Example Output

╔══════════════════════════════════════════════════════╗
β•‘          CVE-2026-14281 SAFE CHECKER                 β•‘
β•‘                                                      β•‘
β•‘       WordPress Plugin Vulnerability Scanner         β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

[*] Checking: https://example.com
[*] Mode: Passive / Non-destructive

Target: https://example.com
HTTP status: 200
WordPress: Detected
Plugin: Detected
Version: 4.8.6
Version source: readme.txt
Confidence: high
CVE status: POTENTIALLY VULNERABLE

Notes:
  β€’ WordPress indicators detected.
  β€’ Plugin readme.txt is accessible.
  β€’ Version 4.8.6 is within the affected range <= 4.8.6.

[!] WARNING: Potentially vulnerable version detected.
[!] Recommended action: update the plugin and investigate the installation.

Command-Line Options

Timeout

Change the HTTP timeout:

py CVE-2026-14281-check.py https://example.com --timeout 20

Default:

10 seconds

Proxy

Useful when inspecting traffic through Burp Suite or another authorized HTTP proxy:

py CVE-2026-14281-check.py https://example.com --proxy http://127.0.0.1:8080

JSON Output

For automation or integration with other security tools:

py CVE-2026-14281-check.py https://example.com --json

Example:

{
  "target": "https://example.com",
  "reachable": true,
  "wordpress_detected": true,
  "plugin_detected": true,
  "version": "4.8.6",
  "version_source": "readme.txt",
  "vulnerable": true,
  "confidence": "high",
  "http_status": 200,
  "notes": [
    "WordPress indicators detected.",
    "Plugin readme.txt is accessible.",
    "Version 4.8.6 is within the affected range <= 4.8.6."
  ]
}

Disable Colors

If output is redirected to another program or terminal:

py CVE-2026-14281-check.py https://example.com --no-color

Exit Codes

The checker provides useful exit codes for scripting and CI/CD environments.

CodeMeaning
0Target is not identified as vulnerable
1Potentially vulnerable version detected
2Error or vulnerability status could not be determined
130User interrupted the scan

Example in Windows:

py CVE-2026-14281-check.py https://example.com

if %ERRORLEVEL% EQU 1 echo Potential vulnerability detected

How Detection Works

The checker does not attempt to exploit CVE-2026-14281.

Instead, it performs several passive checks:

1. WordPress detection

The homepage is inspected for common WordPress indicators such as:

  • wp-content
  • wp-includes
  • wp-json
  • WordPress generator metadata

2. Plugin detection

The response is inspected for references to the affected plugin directory.

3. Version detection

The checker attempts to determine the installed version from:

  • Plugin asset URLs
  • Public readme.txt

4. Version assessment

If a version is identified, it is compared against the known affected range.

Version <= 4.8.6
        β”‚
        β”œβ”€β”€ YES β†’ Potentially vulnerable
        β”‚
        └── NO  β†’ Outside known affected range

Important: False Positives and False Negatives

No passive version checker can guarantee that a target is secure.

Possible limitations include:

  • Plugin assets may be cached.
  • Version information may be hidden.
  • readme.txt may be inaccessible.
  • A security plugin may block requests.
  • A reverse proxy/WAF may modify responses.
  • The plugin may be installed but not publicly detectable.
  • A backported security fix may exist without a version change.
  • A detected version may not accurately represent the code currently running.

Therefore:

UNKNOWN does not mean secure, and NOT IN AFFECTED VERSION RANGE does not constitute a complete security assessment.

For confirmed remediation, verify the installed plugin directly from the WordPress administration environment or package/filesystem information.


Safe by Design

This project intentionally avoids active exploitation.

It does not:

  • create WordPress users
  • assign administrator privileges
  • modify existing accounts
  • attempt OTP bypasses
  • send exploit payloads
  • modify plugin settings
  • upload files
  • execute commands on the target
  • delete or alter data

The purpose is vulnerability identification, not exploitation.


Project Structure

CVE-2026-14281-checker/
β”‚
β”œβ”€β”€ CVE-2026-14281-check.py
β”œβ”€β”€ requirements.txt
β”œβ”€β”€ README.md
β”œβ”€β”€ LICENSE
└── .gitignore

Dependencies

The project uses:

Requests

HTTP client used for communicating with the target.

Colorama

Provides reliable colored terminal output on Windows.

Install all dependencies with:

pip install -r requirements.txt

Responsible Disclosure

If you discover a vulnerable installation that you are authorized to assess:

  1. Confirm the affected version.
  2. Notify the system owner or responsible security team.
  3. Recommend updating to a fixed version.
  4. Avoid unnecessary exploitation.
  5. Preserve relevant evidence without accessing unrelated data.

Do not use this tool to scan systems without authorization.


Disclaimer

This project is provided for defensive security research, vulnerability assessment, education, and authorized penetration testing.

Download Tool