PT-2026-109472 · WordPress · Advanced Ip Blocker

·

CVE-2026-104732

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced IP Blocker versions prior to 8.13.14
Description An authentication bypass exists due to the handle login action() function failing to perform server-side checks to verify that a user completed the first step of password authentication before processing a second-step TOTP submission for a specific user id. An error branch in the function generates a reusable advaipbl-2fa-interim-{user id} nonce in a Location header, and the display 2fa login form step 2() function renders a reusable advaipbl-2fa-verify-{user id} nonce in the HTML. Both nonces are computed against a fixed empty-session context, allowing unauthenticated attackers with a known user id to bypass authentication for 2FA-enabled accounts, including administrators. This is achieved by brute-forcing the unthrottled 6-digit TOTP code, which lacks attempt counters or account lockouts, leading to a fully authenticated session cookie via wp set auth cookie and complete site takeover.
Recommendations Update Advanced IP Blocker to version 8.13.14 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104732

Affected Products

Advanced Ip Blocker