CRITICAL 9.8 CVE-2026-104732 Published 10 Oct 2026

WordPress Advanced IP Blocker Plugin Authentication Bypass Vulnerability

Worried this affects your website?

The Advanced IP Blocker plugin for WordPress is vulnerable to an authentication bypass in all versions up to and including 8.13.13.

The handle_login_action() function performs no server-side check that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed user_id. An error branch unconditionally mints a fresh advaipbl-2fa-interim-{user_id} nonce and delivers it in a Location header to any unauthenticated caller, and display_2fa_login_form_step_2() renders a valid advaipbl-2fa-verify-{user_id} nonce in HTML. Both nonces are computed against a fixed uid=0 empty-session context, making them fully reusable by the attacker.

This allows unauthenticated attackers to bypass authentication for any 2FA-enabled account, including administrators, by brute-forcing an unthrottled 6-digit TOTP code and receiving a fully authenticated session cookie via wp_set_auth_cookie without supplying the account password.

  • Affects all versions up to and including 8.13.13
  • Requires only a known user_id for an account with the plugin's 2FA feature enabled
  • No attempt counter, no account lockout, and no wp_login_failed firing
  • Result is complete site takeover

Reference: CVE-2026-104732 on NVD

← Back to Security News