CRITICAL 9.8 CVE-2026-84737 Published 11 Oct 2026

Freeton WP WordPress Plugin Authentication Bypass Vulnerability

Worried this affects your website?

The Freeton WP WordPress plugin through 1.0.0 contains an authentication bypass vulnerability.

The plugin does not correctly validate the activation code when authenticating a user. This allows unauthenticated attackers to log in as any user whose email address they know, including administrators.

  • Affected versions: through 1.0.0
  • Precondition: attacker knows the target user's email address
  • Impact: full account takeover, including administrator accounts

Reference: CVE-2026-84737 on NVD

← Back to Security News