The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
Title SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T17:41:32.692Z

Reserved: 2026-07-03T09:24:46.210Z

Link: CVE-2026-14557

cve-icon Vulnrichment

Updated: 2026-08-04T15:45:28.000Z

cve-icon NVD

Status : Received

Published: 2026-08-03T07:16:39.533

Modified: 2026-08-04T18:16:43.243

Link: CVE-2026-14557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:15:03Z

Weaknesses