What is CVE-2026-14282?
CVE-2026-14282 is an arbitrary file upload vulnerability in the GoDAM plugin for WordPress (up to version 1.12.2) due to insufficient file type validation in the save_video_file() function. This allows authenticated attackers to upload malicious scripts to the server. Immediate update of the plugin is recommended.
Azərbaycanca: CVE-2026-14282 WordPress üçün GoDAM plaginində (versiya 1.12.2 və əvvəlki) ixtiyari fayl yükləmə zəifliyidir. save_video_file() funksiyasında kifayət qədər fayl tipi yoxlanışı olmadığı üçün autentifikasiyalı hücumçular serverə zərərli skriptlər yükləyə bilər. Plagini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which plugin is affected by CVE-2026-14282 and what is the cause?
The vulnerability affects the GoDAM plugin for WordPress (up to version 1.12.2). The cause is insufficient file type validation in the save_video_file() function.
What is the goal of an attacker exploiting CVE-2026-14282 and how to protect against it?
An authenticated attacker aims to upload malicious scripts to the server. Immediate update of the plugin to the latest version is recommended for protection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.