CRITICAL
9.8 CVE-2026-84737 Published 11 Oct 2026
Freeton WP WordPress Plugin Authentication Bypass Vulnerability
Worried this affects your website?
The Freeton WP WordPress plugin through 1.0.0 contains an authentication bypass vulnerability.
The plugin does not correctly validate the activation code when authenticating a user. This allows unauthenticated attackers to log in as any user whose email address they know, including administrators.
- Affected versions: through 1.0.0
- Precondition: attacker knows the target user's email address
- Impact: full account takeover, including administrator accounts
Reference: CVE-2026-84737 on NVD
← Back to Security News