Retour aux alertes CVE
CVE-2026-14282 CRITICAL CVSS 9.8

CVE-2026-14282 — CRITICAL

Publiée 1 month ago Fiche NVD officielle

Qu'est-ce que c'est ?

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hooked into WPForms' public wpforms_process_before_filter, which trusts the attacker-supplied multipart Content-Type header, preserves the original filename via wp_unique_filename(), and moves the raw upload with $wp_filesystem->move() into a web-served directory — bypassing wp_handle_upload()'s MIME/extension allowlist. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Technologies affectées

Non précisé par la fiche NVD.

Recommandation

Vérifie la disponibilité d'un correctif pour la technologie concernée et applique-le dès que possible. Consulte la fiche NVD pour les références officielles du fournisseur.

Exploits publics connus (1)

nullwhisper/CVE-2026-14282

GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)

Usage responsable : ces liens pointent vers des dépôts publics GitHub à but éducatif ou de test d'intrusion autorisé. N'utilise ces PoC que sur des systèmes que tu es autorisé à tester.