CVE-2026-84737
Freeton WP <= 1.0.0 - Unauthenticated Account Takeover via 'secod' Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.
| Vendor | unknown |
| Product | freeton wp |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown freeton wp
Be the first to know when new unknown vulnerabilities affecting unknown freeton wp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Freeton WP
0 โค 1.0.0
References
Credits
Naoki Kawahigashi WPScan