The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-14557
Mitre link : CVE-2026-14557
CVE.ORG link : CVE-2026-14557
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
