Authentication Flaw in SoftMarket Digital Marketplace Plugin by WordPress
CVE-2026-14557

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 August 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-14557?

The SoftMarket Digital Marketplace WordPress plugin prior to version 1.0.0 suffers from an authentication bypass vulnerability. This occurs due to inadequate validation of authentication tokens within a section of its email verification process. As a result, unauthenticated attackers can compromise user sessions, impersonating verified users by merely supplying their user ID, thereby gaining unauthorized access to potentially sensitive information and functionalities.

Affected Version(s)

SoftMarket β€” Digital Marketplace 0 <= 1.0.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro Pinho
WPScan
.