CVE-2026-84737
Received Received - Intake

Unauthenticated User Login in Freeton WP WordPress Plugin

Vulnerability report for CVE-2026-84737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Freeton WP 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Freeton WP WordPress plugin through version 1.0.0 has a flaw where it does not properly validate activation codes during user authentication. This allows unauthenticated attackers to log in as any user, including administrators, if they know the target's email address.

Detection Guidance

This vulnerability cannot be directly detected via commands as it is a logic flaw in the Freeton WP plugin's authentication mechanism. However, you can check if the plugin is installed by searching for 'freeton-wp' in your WordPress plugins directory or database. If found, assume it is vulnerable if the version is 1.0.0 or below.

Impact Analysis

Attackers could gain unauthorized access to user accounts, including administrative accounts, potentially leading to data theft, unauthorized modifications, or complete site takeover. This could expose sensitive information or allow further attacks on the system.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face legal penalties, loss of trust, and compliance violations due to potential data breaches.

Mitigation Strategies

Immediately disable the Freeton WP plugin if installed. Monitor for unauthorized logins, especially admin accounts. Check for suspicious activity linked to known email addresses. Apply any official patches once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart