CVE-2026-14557 PUBLISHED

SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass

Assigner: WPScan
Reserved: 03.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.

Product Status

Vendor Unknown
Product SoftMarket — Digital Marketplace
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE