External risk intelligence

Freeton WP Plugin Authentication Bypass Allows Full Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84737

This vulnerability affects a WordPress plugin. WordPress sites are commonly deployed as public-facing web applications accessible via the internet, making plugin functionality frequently reachable by external users.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves a WordPress plugin that improperly verifies activation codes, potentially allowing unauthorized access to user accounts, including administrator privileges. The main concern is confirming its relevance and exposure within our environment.

  • Login security flaw in a WordPress plugin.
  • Unauthenticated access to any user account.
  • Confirm if this plugin is in use.

Attack Path

How an attacker could exploit the issue

An attacker can target the Freeton WP plugin on a WordPress site by sending a crafted request. This request leverages a flaw in how the plugin handles activation codes during user authentication. By exploiting this, an unauthenticated attacker can gain access to any user account, including administrative ones, if they know the target user's email address.

  • No authentication required.
  • Malicious activation code submission.
  • Full account takeover.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated attackers could log in as any user if they know the target's email address. This could potentially impact system data and user data by allowing unauthorized access.

  • User accounts could be compromised.
  • Attackers could gain administrative access.
  • Unauthorized actions may be performed.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability in the Freeton WP WordPress plugin, the first step is for application owners and infrastructure teams to locate all instances of the plugin, confirm its reachability and business criticality, and identify the accountable team. Subsequently, a risk-based remediation plan can be developed, potentially involving coordination with the vendor or implementing temporary risk-reduction measures if immediate patching is not feasible.

  • Application owners and infrastructure teams.
  • Confirm plugin reachability and critical assets.
  • Plan remediation and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Freeton WP plugin for WordPress?

Freeton WP is a specialized extension designed for WordPress websites to manage user authentication via activation codes. It acts as an intermediary layer in the login process, intended to verify identity before granting access to site features or administrative dashboards.

What is the security weakness in CVE-2026-84737?

This vulnerability is classified as Improper Authentication (CWE-287). It means the plugin fails to properly validate the activation codes meant to secure the login process, effectively bypassing the gatekeeping mechanism that should prove a user's identity.

How can an attacker trigger this vulnerability?

An attacker initiates this by sending a specifically crafted request to the plugin. They do not need a valid password or account to start this; they only need the email address of a target user, such as an administrator, to successfully impersonate that user.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a high-concern issue because the plugin functions on WordPress, which is typically deployed as a public-facing web application. Since the plugin is often reachable by any internet user, the attack surface is broad.

What steps should I take if I use Freeton WP?

Start by identifying every WordPress instance running this plugin within your environment. Once mapped, confirm which sites are internet-facing, coordinate with the teams responsible for those specific assets, and evaluate your options for disabling the plugin or applying vendor updates.

References