logo

GoDAM WordPress Plugin Arbitrary File Upload — CVE-2026-14282

ID: fbf84877-8023-5652-b00b-06b9c7c321c9

STIX ID: report--fbf84877-8023-5652-b00b-06b9c7c321c9

Feed Name: CosmicBytez Labs

Threat Score
88/100

Date Published: 2026-07-24

Date Updated: 2026-07-26

...
...

**CVE-2026-14282** — critical unauthenticated arbitrary file upload in the GoDAM WordPress plugin (<= 1.12.2) that allows unauthenticated attackers to upload PHP webshells via the save_video_file() AJAX endpoint and achieve remote code execution; mitigate by updating or removing the plugin, auditing uploads and logs, applying WAF rules, and disabling PHP execution in the uploads directory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.