External risk intelligence

SoftMarket Digital Marketplace WordPress Plugin Session Hijacking Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-14557

The vulnerability exists in a WordPress plugin used for a digital marketplace. Plugins of this nature are commonly deployed on internet-facing web servers to facilitate user account management and public-facing marketplace functionality, making them reachable via the public internet in typical deployments.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a popular WordPress plugin used for digital marketplaces, potentially allowing unauthorized access to user accounts. This issue stems from improper handling of authentication tokens during the email verification process, meaning an attacker could gain control of an account without proper credentials, simply by knowing the user's ID. Understanding the scope of this plugin's use within our digital footprint is key to assessing potential impact.

  • Unauthenticated users can hijack accounts.
  • Affects digital marketplace functionality.
  • Confirm usage; assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can initiate an attack by targeting the email verification process of the SoftMarket — Digital Marketplace WordPress plugin. By providing a specific user's ID, an unauthenticated attacker can bypass security checks and obtain a valid session as that user, gaining unauthorized access without needing any credentials.

  • No authentication required.
  • Maliciously crafted verification request.
  • Unauthorized user session access.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated attackers could obtain a valid session as any verified user by supplying only that user's ID, by exploiting a vulnerability in the SoftMarket — Digital Marketplace WordPress plugin's email-verification flow.

  • Verified user sessions are at risk.
  • Attackers supply user ID for token validation.
  • Unauthorized account access may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership

This vulnerability in the SoftMarket — Digital Marketplace WordPress plugin impacts applications that facilitate user registration and management. The primary responsibility for addressing this issue likely falls to the application owners or the platform team managing the WordPress instance, in coordination with the security team. The first practical step is to identify all instances of the SoftMarket plugin, determine its exposure to unauthenticated access, confirm its criticality to business operations, and then plan remediation based on these findings.

  • Application or platform owners should manage resolution.
  • Verify plugin reachability and business criticality first.
  • Plan remediation based on confirmed risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the SoftMarket WordPress plugin?

The SoftMarket plugin is a tool designed for WordPress websites to manage digital marketplaces. It handles essential store functions like user registration, account management, and email verification, enabling owners to sell digital goods directly through their site.

What does CWE-287 mean for CVE-2026-14557?

CWE-287 refers to Improper Authentication. In the context of this CVE, it means the plugin fails to correctly verify the identity of a user during the email-verification process, allowing an attacker to impersonate others without providing the correct credentials.

How can an attacker trigger this vulnerability?

An attacker can trigger this by interacting with the specific email-verification flow in the plugin. If an attacker submits a target user's ID during this process, the system incorrectly grants them an active session. Normal, non-verification traffic does not trigger this specific flaw.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal notes that since this plugin is used for public-facing digital marketplaces, it is typically deployed on internet-facing servers. This means the service is likely reachable from the public internet, increasing the potential for unauthorized access.

What should I do if I use SoftMarket?

First, conduct an inventory to locate every instance of the SoftMarket plugin within your environment. Once identified, evaluate whether the site is accessible to the public, determine its importance to your operations, and work with your team to plan for updates or removal.

References