PatchSiren cyber security CVE debrief
CVE-2026-14557 SoftMarket CVE debrief
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. This vulnerability affects deployments using the plugin's email verification functionality. Defenders should verify plugin version and email verification flow; check for suspicious activity; and monitor vendor advisories for updates. Additional verification tasks may be necessary to confirm affected scope and severity. The evidence for this CVE is limited, and further verification is recommended to ensure the accuracy of the information provided.
- Vendor
- SoftMarket
- Product
- Digital Marketplace (WordPress plugin)
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-08-26
Who should care
Users of SoftMarket — Digital Marketplace WordPress plugin; administrators of WordPress installations with this plugin; security teams responsible for vulnerability management; operators of affected platforms; and anyone responsible for monitoring and detecting potential security threats in their environment should be aware of this vulnerability and take necessary precautions to mitigate its impact.
Technical summary
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow. This could allow unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. The plugin's email verification process seems to be a critical point of vulnerability, as it does not adequately secure user sessions. Affected deployments should prioritize verifying plugin version and configuration, restricting access to email verification functionality, and monitoring for suspicious session activity.
Defensive priority
Verify and limit plugin usage; restrict access to email verification functionality; monitor for suspicious session activity.
Recommended defensive actions
- Verify plugin version and configuration
- Restrict access to email verification functionality
- Monitor for suspicious session activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The evidence for this CVE is limited. The plugin, SoftMarket — Digital Marketplace, through version 1.0.0, does not properly validate an authentication token in one branch of its email-verification flow. This could allow unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. Defenders should verify plugin version and email verification flow; check for suspicious activity; and monitor vendor advisories for updates. Additional verification tasks may be necessary to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14557 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14557
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14557 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14557
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/ed5c7632-a307-43f1-bff0-f70977522e2e/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.