CVE-2026-14557
9.1SoftMarket · Digital Marketplace WordPress plugin
The SoftMarket Digital Marketplace WordPress plugin contains an authentication bypass flaw in its email-verification flow, allowing unauthenticated users to impersonate any verified account.
Executive summary
A critical authentication bypass vulnerability in the SoftMarket Digital Marketplace WordPress plugin allows unauthenticated attackers to hijack any user account.
Vulnerability
The plugin fails to properly validate authentication tokens within its email-verification process. This allows an unauthenticated attacker to supply a target user ID and successfully authenticate as that user, effectively bypassing standard login security measures.
Business impact
The CVSS score of 9.1 underscores the severity of this authentication bypass, as it allows an attacker to assume the identity of any user, including administrators. This can lead to unauthorized access to personal data, financial information, or administrative dashboards, resulting in significant operational and reputational damage.
Remediation
Immediate Action: Update the SoftMarket Digital Marketplace plugin to a version greater than 1.0.0. If an update is not immediately available, consider disabling the plugin to prevent account takeover.
Proactive Monitoring: Audit user account activity and session logs for irregular logins or suspicious account modification behavior.
Compensating Controls: Enforce multi-factor authentication for all user roles where possible, as it may provide an additional layer of defense against account impersonation.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a high-risk scenario for any organization utilizing the SoftMarket plugin for marketplace operations. Immediate updates are required to close the security gap and protect user accounts from unauthorized access and impersonation.