CVE-2026-84737: Freeton WP <= 1.0.0 - Unauthenticated Account Takeover via 'secod' Parameter
Published Oct 11, 2026
·Updated
The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.
Affected Software
1 affected component
Freeton Freeton WP<=1.0.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description