Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-14282: GoDAM <= 1.12.2 - Unauthenticated File Uploads via WPForms Field
CVE-2026-14282 · published 2 months ago
Summary
An outdated version of the GoDAM plugin for WordPress allows hackers to upload any type of file without needing a password. This could potentially allow them to execute malicious code on your website. Update the plugin to the latest version to fix this security issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rtcamp | godam – organize wordpress media library & file manager with unlimited folders for images, videos & more | <= 1.12.2 |
Original advisory text
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and incl...
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hooked into WPForms' public wpforms_process_before_filter, which trusts the attacker-supplied multipart Content-Type header, preserves the original filename via wp_unique_filename(), and moves the raw upload with $wp_filesystem->move() into a web-served directory — bypassing wp_handle_upload()'s MIME/extension allowlist. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ce3ae202-1227-4247-913...
- https://plugins.trac.wordpress.org/browser/godam/tags/1.11.2/inc/classes/wpforms...
- https://plugins.trac.wordpress.org/browser/godam/tags/1.11.2/inc/classes/wpforms...
- https://plugins.trac.wordpress.org/browser/godam/tags/1.12.2/inc/classes/wpforms...
- https://plugins.trac.wordpress.org/browser/godam/tags/1.12.2/inc/classes/wpforms...
- https://plugins.trac.wordpress.org/browser/godam/tags/1.12.2/inc/classes/wpforms...
- https://plugins.trac.wordpress.org/browser/godam/tags/1.11.2/inc/classes/wpforms...
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3607513%40godam&new=3...
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 1%
Type
CWE-434Unrestricted File Upload
Timeline
Published23 Jul 2026
Updated25 Sep 2026
First seen23 Jul 2026
Track software like this
Free during beta