Feed/CVE-2026-14557
CVE-2026-14557CRITICALCVSS 9.1

CVE-2026-14557

Published Aug 3, 2026·Updated Aug 4, 2026

NVD Description

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free