CVE-2026-14282 is a critical arbitrary file upload vulnerability in the GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress, affecting versions up to and including 1.12.2. The flaw is caused by insufficient file type validation in the save_video_file() function, which is hooked into WPForms' public wpforms_process_before_filter. The vulnerable code trusts an attacker-controlled multipart Content-Type header, preserves the supplied filename through wp_unique_filename(), and moves the uploaded file directly into a web-served directory using $wp_filesystem->move(). By bypassing the normal wp_handle_upload() MIME-type and extension allowlist enforcement, the plugin allows unauthenticated attackers to upload arbitrary files to the server. Because the uploaded content can be placed in a web-accessible location, the vulnerability may be leveraged for remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a working Python proof-of-concept exploit plus a small Docker-based WordPress lab for reproducing CVE-2026-14282. The main exploit file, `cve_2026_14282_poc.py`, uses `requests` to fetch a public page, regex-parse WPForms HTML to identify a form ID and GoDAM field ID, submit a multipart POST containing a PHP payload disguised with MIME type `video/mp4`, then probe the expected upload location under `/wp-content/uploads/godam/wpforms/` to confirm code execution. If successful, it invokes arbitrary OS commands through a `c` GET parameter on the uploaded PHP shell. The exploit supports manual form/field selection, automatic detection, brute-force field IDs 1-20, custom shell filename, and custom command execution. The payload is a minimal operational web shell rather than a pure detector, so the repo is an actual exploit and not just a scanner. Supporting files include `lab/docker-compose.yml`, which provisions MySQL, WordPress 6.8, and a WP-CLI container with plugin mounts, and `lab/setup.php`, which programmatically creates a WPForms form containing a `godam_record` field and publishes a page embedding that form. `README.md` documents the vulnerability, usage against live targets, and steps to build the local lab. Notable fingerprintable artifacts include the expected shell path `wp-content/uploads/godam/wpforms/godam-shell.php`, the command parameter `c`, and the local lab endpoint `127.0.0.1:8092`. There is a minor inconsistency in `setup.php`, which prints port 8091 while the Docker lab exposes 8092.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.