CRITICAL
inilerm
CVE published 2026-10-10
CVE-2026-104732
The Advanced IP Blocker plugin for WordPress has a critical vulnerability (CVE-2026-104732) that allows unauthenticated attackers to bypass authentication for 2FA-enabled accounts, including administrators, by brute-forcing a 6-digit TOTP code. This vulnerability exists in all versions up to and including 8.13.13 due to a missing server-side check for step-1 password authentication before processing a ste [truncated]