🔐 CVE Alert

CVE-2026-14557

UNKNOWN 0.0

SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.

Vendor unknown
Product softmarket — digital marketplace
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown softmarket — digital marketplace

Be the first to know when new unknown vulnerabilities affecting unknown softmarket — digital marketplace are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / SoftMarket — Digital Marketplace
0 ≤ 1.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/ed5c7632-a307-43f1-bff0-f70977522e2e/

Credits

Pedro Pinho WPScan