Sceawere

Vulnerability Detail

CVE-2026-84737UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Freeton WP Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Unknown
Product
Freeton WP
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-11T07:17:25.797Z",
  "pubdate": "2026-10-11T07:17:25.797Z",
  "executiveSummary": "A critical authentication bypass vulnerability exists in the Freeton WP WordPress plugin up to and including version 1.0.0. The vulnerability stems from the application failing to correctly validate activation codes when authenticating users. An unauthenticated, remote attacker can exploit this flaw to bypass the authentication flow entirely and log in as any valid user on the target system, provided the attacker knows or discovers that user's email address. Because WordPress administrative accounts rely on registered email addresses, an attacker can leverage this flaw to gain full administrative access to the underlying website without requiring prior authentication or user interaction.\nThe risk implications of this flaw are severe. Successful exploitation enables an unauthenticated actor to achieve complete site takeover, granting them the ability to modify site content, extract sensitive database information, install malicious plugins or backdoors, and disrupt service availability. The attack requires minimal effort, as target email addresses can often be obtained through public sources or standard enumeration methods. Given the absence of privilege or interaction requirements, all sites running vulnerable versions of the Freeton WP plugin face immediate, critical exposure to unauthorized access and system compromise. Defending against this vulnerability requires immediate containment and remediation actions.",
  "technicalDetails": "The Freeton WP WordPress plugin, through version 1.0.0, includes a user authentication mechanism designed to authenticate accounts using an activation code verification sequence. A critical logic flaw resides within the plugin's code execution path responsible for processing these activation requests. Specifically, when a request to authenticate via an activation code is received, the underlying code fails to perform necessary cryptographic or strict equality validation checks between the activation code supplied in the incoming request payload and the genuine token associated with the target user in the site's database.\nDue to this flawed validation logic, the authentication module treats the presence of a user's email address as the primary criteria for identity verification, bypassing the essential condition that requires the activation code to be valid and active. Consequently, any unauthenticated attacker operating across the network can interact directly with the vulnerable authentication endpoint to forge a legitimate login session for any account on the WordPress installation.\nThe complete end-to-end attack flow proceeds as follows:\n1. Target Identification and Enumeration: The remote attacker identifies a WordPress instance running the Freeton WP plugin up to version 1.0.0. The attacker retrieves the target user's email address. On standard WordPress deployments, administrative and user email addresses can frequently be enumerated via publicly accessible resources, such as REST API endpoints (/wp/v2/users), RSS feeds, author archive parameters, or public comment sections.\n2. Payload Construction: The attacker crafts an HTTP request targeting the plugin's specific authentication action handler. The payload includes the target user's valid email address alongside an arbitrary, empty, or dummy activation code parameter.\n3. Logic Flaw Execution: Upon receiving the request, the server executes the plugin's authentication function. Because the function omits rigorous validation logic for the activation code, the execution path evaluates the submission as successful based primarily on the valid email reference.\n4. Session Hijacking and Token Issuance: The application sets the official WordPress authentication cookies (wordpress_logged_in_*) corresponding to the targeted user identity, returning a successful authentication response to the attacker's client.\n5. Post-Exploitation and Elevation: The attacker inherits all privileges bound to the target account. If the targeted email address belongs to an administrator, the attacker secures unrestricted access to the WordPress administrative dashboard (/wp-admin/). From this elevated vantage point, the attacker can execute arbitrary PHP code via theme or plugin editing, access the underlying database, manipulate user management settings, or establish persistent backdoors across the environment."
}
CVE-2026-84737: Freeton WP Authentication Bypass Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere