Authentication Flaw in SoftMarket Digital Marketplace Plugin by WordPress
CVE-2026-14557
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 August 2026
Badges
πΎ Exploit Existsπ‘ Public PoC
What is CVE-2026-14557?
The SoftMarket Digital Marketplace WordPress plugin prior to version 1.0.0 suffers from an authentication bypass vulnerability. This occurs due to inadequate validation of authentication tokens within a section of its email verification process. As a result, unauthenticated attackers can compromise user sessions, impersonating verified users by merely supplying their user ID, thereby gaining unauthorized access to potentially sensitive information and functionalities.
Affected Version(s)
SoftMarket β Digital Marketplace 0 <= 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.