一个轻量级、对 Windows 友好的 Python 安全检查工具,用于识别可能受 CVE-2026-14281 影响的 WordPress 安装。
该工具执行被动、非破坏性检查。它不会利用该漏洞、创建账户、修改权限或更改目标网站。
仅供授权安全测试使用。 仅扫描您拥有或已获得明确评估许可的网站和系统。
readme.txt| 字段 | 详情 |
|---|---|
| CVE | CVE-2026-14281 |
| 产品 | Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code |
| 受影响版本 | ≤ 4.8.6 |
| 已知修复版本 | 4.8.7+ |
| 扫描器类型 | 被动 / 非破坏性 |
该检查工具使用检测到的插件版本来判断该安装是否落在已知受影响版本范围内。
结果为 POTENTIALLY VULNERABLE(可能易受攻击)意味着检测到的版本落在受影响范围内。它不能替代完整的安全评估。
requestscolorama支持的操作系统:
克隆仓库:
git clone https://github.com/YOUR-USERNAME/CVE-2026-14281-checker.git
cd CVE-2026-14281-checker
安装依赖:
py -m pip install -r requirements.txt
在 Linux/macOS 上:
python3 -m pip install -r requirements.txt
Windows:
py CVE-2026-14281-check.py https://example.com
Linux/macOS:
python3 CVE-2026-14281-check.py https://example.com
您也可以提供不带协议的主机名:
py CVE-2026-14281-check.py example.com
检查工具会自动对其进行规范化。
╔══════════════════════════════════════════════════════╗
║ CVE-2026-14281 SAFE CHECKER ║
║ ║
║ WordPress Plugin Vulnerability Scanner ║
╚══════════════════════════════════════════════════════╝
[*] Checking: https://example.com
[*] Mode: Passive / Non-destructive
Target: https://example.com
HTTP status: 200
WordPress: Detected
Plugin: Detected
Version: 4.8.6
Version source: readme.txt
Confidence: high
CVE status: POTENTIALLY VULNERABLE
Notes:
• WordPress indicators detected.
• Plugin readme.txt is accessible.
• Version 4.8.6 is within the affected range <= 4.8.6.
[!] WARNING: Potentially vulnerable version detected.
[!] Recommended action: update the plugin and investigate the installation.
更改 HTTP 超时:
py CVE-2026-14281-check.py https://example.com --timeout 20
默认值:
10 seconds
在通过 Burp Suite 或其他授权 HTTP 代理检查流量时非常有用:
py CVE-2026-14281-check.py https://example.com --proxy http://127.0.0.1:8080
用于自动化或与其他安全工具集成:
py CVE-2026-14281-check.py https://example.com --json
示例:
{
"target": "https://example.com",
"reachable": true,
"wordpress_detected": true,
"plugin_detected": true,
"version": "4.8.6",
"version_source": "readme.txt",
"vulnerable": true,
"confidence": "high",
"http_status": 200,
"notes": [
"WordPress indicators detected.",
"Plugin readme.txt is accessible.",
"Version 4.8.6 is within the affected range <= 4.8.6."
]
}
如果输出被重定向到其他程序或终端:
py CVE-2026-14281-check.py https://example.com --no-color
该检查工具为脚本和 CI/CD 环境提供了有用的退出代码。
| 代码 | 含义 |
|---|---|
0 | 目标未被识别为易受攻击 |
1 | 检测到可能易受攻击的版本 |
2 | 错误或无法确定漏洞状态 |
130 | 用户中断了扫描 |
Windows 中的示例:
py CVE-2026-14281-check.py https://example.com
if %ERRORLEVEL% EQU 1 echo Potential vulnerability detected
该检查工具不会尝试利用 CVE-2026-14281。
相反,它会执行若干被动检查:
检查主页中常见的 WordPress 特征,例如:
wp-contentwp-includeswp-json检查响应中是否引用了受影响的插件目录。
检查工具尝试从以下来源确定已安装的版本:
readme.txt如果识别出版本,则将其与已知受影响范围进行比较。
Version <= 4.8.6
│
├── YES → Potentially vulnerable
│
└── NO → Outside known affected range
任何被动版本检查工具都无法保证目标安全。
可能的局限性包括:
readme.txt 可能无法访问。因此:
UNKNOWN(未知)并不意味着安全,NOT IN AFFECTED VERSION RANGE(不在受影响版本范围内)也不构成完整的安全评估。
如需确认修复情况,请直接从 WordPress 管理环境或包/文件系统信息中验证已安装的插件。
本项目有意避免主动利用。
它不会:
其目的是漏洞识别,而非利用。
CVE-2026-14281-checker/
│
├── CVE-2026-14281-check.py
├── requirements.txt
├── README.md
├── LICENSE
└── .gitignore
本项目使用:
用于与目标通信的 HTTP 客户端。
在 Windows 上提供可靠的彩色终端输出。
使用以下命令安装所有依赖项:
pip install -r requirements.txt
如果您发现了一个您有权评估的易受攻击的安装:
请勿使用此工具扫描未经授权的系统。
本项目仅供防御性安全研究、漏洞评估、教育和授权渗透测试使用。
作者不对因使用本软件而导致的误用、未经授权的扫描、损害、数据丢失、服务中断或任何其他后果负责。
使用本项目即表示您同意遵守所有适用的法律、法规、合同和授权要求。
本项目在 MIT 许可证下发布。
v1.0.0
首次公开发布。