What is CVE-2026-14557?
CVE-2026-14557 allows unauthenticated attackers to obtain a valid session as any verified user in the SoftMarket – Digital Marketplace WordPress plugin (through version 1.0.0) by exploiting improper authentication token validation in the email-verification flow, requiring only the user ID. Affected systems should update or temporarily disable the plugin.
Azərbaycanca: CVE-2026-14557, SoftMarket – Digital Marketplace WordPress plaginində (1.0.0 versiyasına qədər) autentifikasiya tokeninin düzgün yoxlanılmaması səbəbindən autentifikasiya olunmamış hücumçulara yalnız istifadəçi ID-si ilə hər hansı təsdiqlənmiş istifadəçi kimi sessiya əldə etməyə imkan verir. Təsirlənən sistemlərdə plagini dərhal yeniləmək və ya müvəqqəti olaraq söndürmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
How is CVE-2026-14557 exploited in the SoftMarket plugin?
CVE-2026-14557 allows unauthenticated attackers to obtain a valid session as any verified user in the SoftMarket – Digital Marketplace WordPress plugin by exploiting improper authentication token validation, requiring only the user ID.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.