PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14557 SoftMarket CVE debrief

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. This vulnerability affects deployments using the plugin's email verification functionality. Defenders should verify plugin version and email verification flow; check for suspicious activity; and monitor vendor advisories for updates. Additional verification tasks may be necessary to confirm affected scope and severity. The evidence for this CVE is limited, and further verification is recommended to ensure the accuracy of the information provided.

Vendor
SoftMarket
Product
Digital Marketplace (WordPress plugin)
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-26
Advisory published
2026-08-03
Advisory updated
2026-08-26

Who should care

Users of SoftMarket — Digital Marketplace WordPress plugin; administrators of WordPress installations with this plugin; security teams responsible for vulnerability management; operators of affected platforms; and anyone responsible for monitoring and detecting potential security threats in their environment should be aware of this vulnerability and take necessary precautions to mitigate its impact.

Technical summary

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow. This could allow unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. The plugin's email verification process seems to be a critical point of vulnerability, as it does not adequately secure user sessions. Affected deployments should prioritize verifying plugin version and configuration, restricting access to email verification functionality, and monitoring for suspicious session activity.

Defensive priority

Verify and limit plugin usage; restrict access to email verification functionality; monitor for suspicious session activity.

Recommended defensive actions

  • Verify plugin version and configuration
  • Restrict access to email verification functionality
  • Monitor for suspicious session activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The evidence for this CVE is limited. The plugin, SoftMarket — Digital Marketplace, through version 1.0.0, does not properly validate an authentication token in one branch of its email-verification flow. This could allow unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. Defenders should verify plugin version and email verification flow; check for suspicious activity; and monitor vendor advisories for updates. Additional verification tasks may be necessary to confirm affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14557 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14557

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14557 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14557

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.