Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in a popular WordPress plugin used for digital marketplaces, potentially allowing unauthorized access to user accounts. This issue stems from improper handling of authentication tokens during the email verification process, meaning an attacker could gain control of an account without proper credentials, simply by knowing the user's ID. Understanding the scope of this plugin's use within our digital footprint is key to assessing potential impact.
- Unauthenticated users can hijack accounts.
- Affects digital marketplace functionality.
- Confirm usage; assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker can initiate an attack by targeting the email verification process of the SoftMarket — Digital Marketplace WordPress plugin. By providing a specific user's ID, an unauthenticated attacker can bypass security checks and obtain a valid session as that user, gaining unauthorized access without needing any credentials.
- No authentication required.
- Maliciously crafted verification request.
- Unauthorized user session access.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, unauthenticated attackers could obtain a valid session as any verified user by supplying only that user's ID, by exploiting a vulnerability in the SoftMarket — Digital Marketplace WordPress plugin's email-verification flow.
- Verified user sessions are at risk.
- Attackers supply user ID for token validation.
- Unauthorized account access may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-World Ownership
This vulnerability in the SoftMarket — Digital Marketplace WordPress plugin impacts applications that facilitate user registration and management. The primary responsibility for addressing this issue likely falls to the application owners or the platform team managing the WordPress instance, in coordination with the security team. The first practical step is to identify all instances of the SoftMarket plugin, determine its exposure to unauthenticated access, confirm its criticality to business operations, and then plan remediation based on these findings.
- Application or platform owners should manage resolution.
- Verify plugin reachability and business criticality first.
- Plan remediation based on confirmed risk exposure.