CVE-2026-14557
SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
| Vendor | unknown |
| Product | softmarket — digital marketplace |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown softmarket — digital marketplace
Be the first to know when new unknown vulnerabilities affecting unknown softmarket — digital marketplace are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / SoftMarket — Digital Marketplace
0 ≤ 1.0.0
References
Credits
Pedro Pinho WPScan