PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104732 inilerm CVE debrief

The Advanced IP Blocker plugin for WordPress has a critical vulnerability (CVE-2026-104732) that allows unauthenticated attackers to bypass authentication for 2FA-enabled accounts, including administrators, by brute-forcing a 6-digit TOTP code. This vulnerability exists in all versions up to and including 8.13.13 due to a missing server-side check for step-1 password authentication before processing a step-2 TOTP submission.

Vendor
inilerm
Product
Advanced IP Blocker
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress site administrators and owners who use the Advanced IP Blocker plugin, especially those with 2FA-enabled accounts, should assess their exposure and take immediate action to update the plugin and restrict access to sensitive areas of the site.

Why it matters

CVE-2026-104732 is a critical vulnerability in the Advanced IP Blocker plugin for WordPress that allows unauthenticated attackers to bypass authentication for 2FA-enabled accounts. WordPress site administrators and owners should assess their exposure and take immediate action to update the plugin and restrict access to sensitive areas of the site.

  • Unauthenticated attackers can bypass authentication for 2FA-enabled accounts
  • Administrators and other privileged users are at risk of account compromise
  • Brute-forcing a 6-digit TOTP code is possible due to lack of rate limiting or account lockout
  • Verification of plugin version and 2FA configuration is necessary to determine exposure

Technical summary

The Advanced IP Blocker plugin for WordPress is vulnerable to authentication bypass due to a missing server-side check for step-1 password authentication before processing a step-2 TOTP submission. This allows unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators. The vulnerability exists in all versions up to and including 8.13.13. The `handle_login_action()` function does not perform a server-side check for step-1 password authentication before processing a step-2 TOTP submission, and an error branch in the function unconditionally mints a fresh nonce and delivers it in a Location header to any unauthenticated caller.

Defensive priority

High

Recommended defensive actions

  • Immediately update the Advanced IP Blocker plugin to a version that fixes this vulnerability
  • Review and restrict access to sensitive areas of the WordPress site
  • Monitor for suspicious login attempts and implement additional security measures such as IP blocking or rate limiting
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by the `handle_login_action()` function not performing a server-side check for step-1 password authentication before processing a step-2 TOTP submission. An error branch in the function unconditionally mints a fresh nonce and delivers it in a Location header to any unauthenticated caller.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104732 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104732

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104732 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104732

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Bindin

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104732.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-main.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-2fa-manager.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3725139/advanced-ip-blocker/trunk/includes/class-advaipbl-main.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.