Impact
The Freeton WP WordPress plugin through version 1.0.0 fails to validate the activation code during user authentication, allowing an unauthenticated attacker to provide a known email address and the insecure ‘secod’ parameter to log in as that user. This flaw permits full control over any targeted account, including administrators, without requiring any prior credentials. The weakness is a classic case of improper authentication, classified as CWE‑287.
Affected Systems
The vulnerability affects any deployment of the Freeton WP plugin for WordPress that is version 1.0.0 or earlier. Site administrators should verify the plugin version and, if it falls within the affected range, consider the plugin a liability until a fix is applied.
Risk and Exploitability
The vulnerability can be exploited by sending a crafted HTTP request that includes the ‘secod’ parameter and the target user’s email. No user authentication is required; hence the attack vector is likely Internet-facing. Based on the description, it is inferred that the exploitation path is straightforward and does not need additional privileges. The EPSS score is not reported, the vulnerability is not listed in CISA KEV, and no CVSS score is provided, so the exact likelihood of exploitation remains unknown, but the absence of defensive checks makes it highly exploitable once discovered.
OpenCVE Enrichment