PatchSiren cyber security CVE debrief
CVE-2026-104732 inilerm CVE debrief
The Advanced IP Blocker plugin for WordPress has a critical vulnerability (CVE-2026-104732) that allows unauthenticated attackers to bypass authentication for 2FA-enabled accounts, including administrators, by brute-forcing a 6-digit TOTP code. This vulnerability exists in all versions up to and including 8.13.13 due to a missing server-side check for step-1 password authentication before processing a step-2 TOTP submission.
- Vendor
- inilerm
- Product
- Advanced IP Blocker
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress site administrators and owners who use the Advanced IP Blocker plugin, especially those with 2FA-enabled accounts, should assess their exposure and take immediate action to update the plugin and restrict access to sensitive areas of the site.
Why it matters
CVE-2026-104732 is a critical vulnerability in the Advanced IP Blocker plugin for WordPress that allows unauthenticated attackers to bypass authentication for 2FA-enabled accounts. WordPress site administrators and owners should assess their exposure and take immediate action to update the plugin and restrict access to sensitive areas of the site.
- Unauthenticated attackers can bypass authentication for 2FA-enabled accounts
- Administrators and other privileged users are at risk of account compromise
- Brute-forcing a 6-digit TOTP code is possible due to lack of rate limiting or account lockout
- Verification of plugin version and 2FA configuration is necessary to determine exposure
Technical summary
The Advanced IP Blocker plugin for WordPress is vulnerable to authentication bypass due to a missing server-side check for step-1 password authentication before processing a step-2 TOTP submission. This allows unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators. The vulnerability exists in all versions up to and including 8.13.13. The `handle_login_action()` function does not perform a server-side check for step-1 password authentication before processing a step-2 TOTP submission, and an error branch in the function unconditionally mints a fresh nonce and delivers it in a Location header to any unauthenticated caller.
Defensive priority
High
Recommended defensive actions
- Immediately update the Advanced IP Blocker plugin to a version that fixes this vulnerability
- Review and restrict access to sensitive areas of the WordPress site
- Monitor for suspicious login attempts and implement additional security measures such as IP blocking or rate limiting
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by the `handle_login_action()` function not performing a server-side check for step-1 password authentication before processing a step-2 TOTP submission. An error branch in the function unconditionally mints a fresh nonce and delivers it in a Location header to any unauthenticated caller.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104732 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104732
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104732 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104732
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Bindin
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104732.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-main.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-2fa-manager.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3725139/advanced-ip-blocker/trunk/includes/class-advaipbl-main.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.