Authentication Bypass in Advanced IP Blocker WordPress Plugin
An authentication bypass vulnerability in the Advanced IP Blocker WordPress plugin enables unauthenticated attackers to brute-force MFA tokens and achieve complete site takeover via reusable nonces and lack of rate limiting.
CVE search metadata
CVE search record: CVE-2026-104732. Severity: critical. CVSS: 9.8. KEV: no. Product: Advanced IP Blocker (<= 8.13.13). Brief: Authentication Bypass in Advanced IP Blocker WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-advanced-ip-blocker-auth-bypass/
The Advanced IP Blocker plugin for WordPress is vulnerable to an authentication bypass in all versions up to and including 8.13.13. The vulnerability, tracked as CVE-2026-104732, exists because the handle_login_action() function fails to perform server-side validation that a user has successfully completed password authentication before processing step-two TOTP submissions.
The plugin generates authentication nonces (advaipbl-2fa-interim-{user_id} and advaipbl-2fa-verify-{user_id}) based on a fixed, empty-session context, making them fully reusable by an attacker. Furthermore, the 2FA verification endpoint lacks rate limiting, account lockout mechanisms, and does not fire standard wp_login_failed hooks. An unauthenticated attacker knowing a valid user ID can leverage these flaws to brute-force a 6-digit TOTP code and obtain a valid authenticated session cookie via wp_set_auth_cookie. This flaw allows for full site takeover, including administrator accounts, without ever requiring the account password.
Impact
Successful exploitation results in full unauthorized access to the WordPress environment as the targeted user. If an administrator account is targeted, the attacker gains complete control over the site, allowing for the execution of arbitrary code, data exfiltration, and persistence. Given the lack of rate limiting and logging on the 2FA verification process, attacks may remain undetected until the compromise is already complete.
Recommendation
- Update the Advanced IP Blocker plugin to the latest version immediately once a patch is released to mitigate CVE-2026-104732.
- Disable the 2FA feature of the Advanced IP Blocker plugin if immediate updating is not possible, and rely on standard WordPress authentication or alternative, patched MFA providers.
- Review web server access logs for repeated POST requests to the plugin's login endpoint targeting specific user IDs.
- Monitor for unauthorized administrative sessions or modifications to user account privileges.
Immediate actions
Audit WordPress installations for usage of Advanced IP Blocker plugin
Mitigations
Disable 2FA feature in Advanced IP Blocker plugin until a patched version (version > 8.13.13) is available
CVE-2026-104732
Detection coverage 1
Detect CVE-2026-104732 Exploitation Attempt
highDetects high-frequency POST requests to the Advanced IP Blocker plugin TOTP verification endpoint, indicating potential brute-force activity.
Detection queries are available on the platform. Get full rules →