CVE-2026-14557
Received Received - Intake

Authentication Bypass in SoftMarket WordPress Plugin

Vulnerability report for CVE-2026-14557, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The SoftMarket β€” Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
softmarket digital_marketplace 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The SoftMarket WordPress plugin through version 1.0.0 has a flaw in its email-verification process. It fails to properly validate an authentication token in one part of the flow. This allows attackers to bypass verification and obtain a valid session for any user by providing only that user's ID.

Impact Analysis

An attacker could impersonate any verified user on the platform, gaining access to their account and sensitive data. This could lead to unauthorized actions, data theft, or further exploitation of the compromised accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection requirements. For HIPAA, it may compromise protected health information, risking compliance with privacy and security rules.

Mitigation Strategies

Update the SoftMarket Digital Marketplace WordPress plugin to the latest version immediately. If an update is not available, consider disabling the plugin until a patch is released. Review user sessions and invalidate any suspicious active sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14557. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart