Arbitrary File Upload Vulnerability in GoDAM Media Library Plugin for WordPress
CVE-2026-14282

9.8CRITICAL

What is CVE-2026-14282?

The GoDAM plugin for WordPress is susceptible to arbitrary file uploads due to inadequate validation of file types in the save_video_file() function. This vulnerability allows unauthenticated users to upload malicious files to the server, potentially leading to remote code execution. The flaw arises from the plugin's reliance on the multipart Content-Type header provided by the attacker, alongside the preservation of the original filename without proper checks. As a result, the plugin may inadvertently move uploaded files into directories accessible via the web, posing significant security risks to WordPress sites utilizing this plugin.

Affected Version(s)

GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more 0 <= 1.12.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CHOIGYEONGMIN
.