Arbitrary File Upload Vulnerability in GoDAM Media Library Plugin for WordPress
⚠️ CVE-Referenzen:
CVE-2026-14282
WordPress - Godam – Organize WordPress Media Library & File Manager With Unlimited Folders For Images, Videos & More - CRITICAL - CVE-2026-14282.
The GoDAM plugin for WordPress is susceptible to arbitrary file uploads due to inadequate validation of file types in the save_video_file() function. This vulnerability allows unauthenticated users to upload malicious files to the server, potentially leading to remote code execution. The flaw arises from the plugin's reliance on the multipart Content-Type header provided by the attacker, alongside the preservation of the original filename without proper checks. As a result, the plugin may inadvertently move uploaded files into directories accessible via the web, posing significant security risks to WordPress sites utilizing this plugin.
Quelle: securityvulnerability.io