PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14557 SoftMarket CVE debrief

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. This vulnerability affects deployments using the plugin's email verification functionality. Defenders should verify plugin version and email verification flow; check for suspicious activity; and monitor vendor advisories for updates. Additional verification tasks may be necessary to confirm affected scope and severity. The evidence for this CVE is limited, and further verification is recommended to ensure the accuracy of the information provided.

Vendor
SoftMarket
Product
Digital Marketplace (WordPress plugin)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-03
Advisory published
2026-08-03
Advisory updated
2026-08-03

Who should care

Users of SoftMarket — Digital Marketplace WordPress plugin; administrators of WordPress installations with this plugin; security teams responsible for vulnerability management; operators of affected platforms; and anyone responsible for monitoring and detecting potential security threats in their environment should be aware of this vulnerability and take necessary precautions to mitigate its impact.

Technical summary

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow. This could allow unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. The plugin's email verification process seems to be a critical point of vulnerability, as it does not adequately secure user sessions. Affected deployments should prioritize verifying plugin version and configuration, restricting access to email verification functionality, and monitoring for suspicious session activity.

Defensive priority

Verify and limit plugin usage; restrict access to email verification functionality; monitor for suspicious session activity.

Recommended defensive actions

  • Verify plugin version and configuration
  • Restrict access to email verification functionality
  • Monitor for suspicious session activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The evidence for this CVE is limited. The plugin, SoftMarket — Digital Marketplace, through version 1.0.0, does not properly validate an authentication token in one branch of its email-verification flow. This could allow unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. Defenders should verify plugin version and email verification flow; check for suspicious activity; and monitor vendor advisories for updates. Additional verification tasks may be necessary to confirm affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T07:16:39.533Z and has not been modified since then.