PatchSiren

inilerm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL inilerm CVE published 2026-10-10

CVE-2026-104732

The Advanced IP Blocker plugin for WordPress has a critical vulnerability (CVE-2026-104732) that allows unauthenticated attackers to bypass authentication for 2FA-enabled accounts, including administrators, by brute-forcing a 6-digit TOTP code. This vulnerability exists in all versions up to and including 8.13.13 due to a missing server-side check for step-1 password authentication before processing a ste [truncated]