Description
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
Published: 2026-08-03
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SoftMarket — Digital Marketplace WordPress plugin lacks proper validation of an authentication token in one branch of its email‑verification workflow, allowing an attacker who supplies only the numeric identifier of a verified user to obtain a valid session token for that user without providing any credentials. This flaw directly maps to the improper authentication weakness described in CWE‑287 and grants the attacker full access to the victim’s account to read, modify, or delete protected data, impersonate customers, or launch further attacks from within the application.

Affected Systems

Any site running the SoftMarket — Digital Marketplace WordPress plugin version 1.0.0 or older is affected. The plugin is identified as “Unknown:SoftMarket — Digital Marketplace” in the CVE record.

Risk and Exploitability

The vulnerability is exploitable without prior authentication, which indicates a high likelihood of abuse, especially on publicly accessible WordPress installations. Based on the description, the attack vector is via supplying a user ID in the email‑verification flow, and the EPSS score suggests a very low but nonzero exploitation probability. The issue is not listed in the CISA KEV catalog, but the CVSS score of 9.1 confirms the vulnerability’s high severity and the potential for system‑wide damage through account takeover.

Generated by OpenCVE AI on August 4, 2026 at 22:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SoftMarket — Digital Marketplace plugin to a version that properly validates the authentication token, if such an update exists.
  • If no patch is available, disable or uninstall the vulnerable plugin to eliminate the attack surface.
  • Implement additional authentication safeguards such as two‑factor authentication or stricter role‑based access controls to reduce the impact of any future similar flaws.

Generated by OpenCVE AI on August 4, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
Title SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T17:41:32.692Z

Reserved: 2026-07-03T09:24:46.210Z

Link: CVE-2026-14557

cve-icon Vulnrichment

Updated: 2026-08-04T15:45:28.000Z

cve-icon NVD

Status : Received

Published: 2026-08-03T07:16:39.533

Modified: 2026-08-04T18:16:43.243

Link: CVE-2026-14557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:15:03Z

Weaknesses