Description
The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.
Published: 2026-10-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass leading to account takeover
Action: Immediate Patch
AI Analysis

Impact

The Freeton WP WordPress plugin through version 1.0.0 fails to validate the activation code during user authentication, allowing an unauthenticated attacker to provide a known email address and the insecure ‘secod’ parameter to log in as that user. This flaw permits full control over any targeted account, including administrators, without requiring any prior credentials. The weakness is a classic case of improper authentication, classified as CWE‑287.

Affected Systems

The vulnerability affects any deployment of the Freeton WP plugin for WordPress that is version 1.0.0 or earlier. Site administrators should verify the plugin version and, if it falls within the affected range, consider the plugin a liability until a fix is applied.

Risk and Exploitability

The vulnerability can be exploited by sending a crafted HTTP request that includes the ‘secod’ parameter and the target user’s email. No user authentication is required; hence the attack vector is likely Internet-facing. Based on the description, it is inferred that the exploitation path is straightforward and does not need additional privileges. The EPSS score is not reported, the vulnerability is not listed in CISA KEV, and no CVSS score is provided, so the exact likelihood of exploitation remains unknown, but the absence of defensive checks makes it highly exploitable once discovered.

Generated by OpenCVE AI on October 11, 2026 at 08:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Freeton WP plugin to a version newer than 1.0.0 as soon as it becomes available.
  • If an update is not yet released, restrict the endpoint that accepts the ‘secod’ parameter so that only authenticated administrators can access it, or block the parameter via firewall or web application firewall rules.
  • Disable the activation code feature or remove the ‘secod’ parameter entirely until a secure implementation is published.

Generated by OpenCVE AI on October 11, 2026 at 08:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.
Title Freeton WP <= 1.0.0 - Unauthenticated Account Takeover via 'secod' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:44.539Z

Reserved: 2026-09-02T08:35:33.361Z

Link: CVE-2026-84737

cve-icon Vulnrichment

Updated: 2026-10-11T11:23:45.637Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:25.797

Modified: 2026-10-11T12:17:23.923

Link: CVE-2026-84737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T08:15:17Z

Weaknesses