PT-2026-109472 · WordPress · Advanced Ip Blocker
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advanced IP Blocker versions prior to 8.13.14
Description
An authentication bypass exists due to the
handle login action() function failing to perform server-side checks to verify that a user completed the first step of password authentication before processing a second-step TOTP submission for a specific user id. An error branch in the function generates a reusable advaipbl-2fa-interim-{user id} nonce in a Location header, and the display 2fa login form step 2() function renders a reusable advaipbl-2fa-verify-{user id} nonce in the HTML. Both nonces are computed against a fixed empty-session context, allowing unauthenticated attackers with a known user id to bypass authentication for 2FA-enabled accounts, including administrators. This is achieved by brute-forcing the unthrottled 6-digit TOTP code, which lacks attempt counters or account lockouts, leading to a fully authenticated session cookie via wp set auth cookie and complete site takeover.Recommendations
Update Advanced IP Blocker to version 8.13.14 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Ip Blocker