GoDAM WordPress Plugin Arbitrary File Upload — CVE-2026-14282
ID: fbf84877-8023-5652-b00b-06b9c7c321c9
STIX ID: report--fbf84877-8023-5652-b00b-06b9c7c321c9
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-14282** — critical unauthenticated arbitrary file upload in the GoDAM WordPress plugin (<= 1.12.2) that allows unauthenticated attackers to upload PHP webshells via the save_video_file() AJAX endpoint and achieve remote code execution; mitigate by updating or removing the plugin, auditing uploads and logs, applying WAF rules, and disabling PHP execution in the uploads directory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
