SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14557

CRITICAL · CVSS 9.1 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The SoftMarket — Digital Marketplace WordPress plugin versions up to 1.0.0 are vulnerable due to inadequate validation of authentication tokens in the email-verification process. This flaw enables unauthenticated attackers to gain access to valid user sessions by simply providing the ID of a verified user, potentially leading to unauthorized actions within the application. WordPress site administrators using this plugin should prioritize patching or updating to mitigate the risk of session hijacking.

CVE
CVE-2026-14557
Severity
CRITICAL
CVSS
9.1
EPSS
0.39%
WordPress

Original NVD Description

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.