Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-14557: SoftMarket <= 1.0.0: Unauthenticated Account Takeover via Email Verification

CVE-2026-14557 · published 1 month ago
Summary

The SoftMarket plugin for WordPress allows attackers to take control of any user's account without a password, by exploiting a flaw in its email verification process. This puts all verified users at risk of their accounts being compromised. Update the plugin to a secure version to prevent this vulnerability.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown softmarket — digital marketplace <= 1.0.0
Original advisory text
SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published3 Aug 2026
Updated27 Sep 2026
First seen3 Aug 2026
Sources
CVE-2026-14557 · MITRE
Track software like this
Free during beta