{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/advanced-ip-blocker--8.13.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:advanced_ip_blocker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-104732"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Advanced IP Blocker (\u003c= 8.13.13)"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","wordpress","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Advanced IP Blocker plugin for WordPress is vulnerable to an authentication bypass in all versions up to and including 8.13.13. The vulnerability, tracked as CVE-2026-104732, exists because the \u003ccode\u003ehandle_login_action()\u003c/code\u003e function fails to perform server-side validation that a user has successfully completed password authentication before processing step-two TOTP submissions.\u003c/p\u003e\n\u003cp\u003eThe plugin generates authentication nonces (\u003ccode\u003eadvaipbl-2fa-interim-{user_id}\u003c/code\u003e and \u003ccode\u003eadvaipbl-2fa-verify-{user_id}\u003c/code\u003e) based on a fixed, empty-session context, making them fully reusable by an attacker. Furthermore, the 2FA verification endpoint lacks rate limiting, account lockout mechanisms, and does not fire standard \u003ccode\u003ewp_login_failed\u003c/code\u003e hooks. An unauthenticated attacker knowing a valid user ID can leverage these flaws to brute-force a 6-digit TOTP code and obtain a valid authenticated session cookie via \u003ccode\u003ewp_set_auth_cookie\u003c/code\u003e. This flaw allows for full site takeover, including administrator accounts, without ever requiring the account password.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full unauthorized access to the WordPress environment as the targeted user. If an administrator account is targeted, the attacker gains complete control over the site, allowing for the execution of arbitrary code, data exfiltration, and persistence. Given the lack of rate limiting and logging on the 2FA verification process, attacks may remain undetected until the compromise is already complete.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Advanced IP Blocker plugin to the latest version immediately once a patch is released to mitigate CVE-2026-104732.\u003c/li\u003e\n\u003cli\u003eDisable the 2FA feature of the Advanced IP Blocker plugin if immediate updating is not possible, and rely on standard WordPress authentication or alternative, patched MFA providers.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for repeated POST requests to the plugin's login endpoint targeting specific user IDs.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized administrative sessions or modifications to user account privileges.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T05:33:42Z","date_published":"2026-10-10T05:33:42Z","id":"https://feed.craftedsignal.io/briefs/2026-10-advanced-ip-blocker-auth-bypass/","summary":"An authentication bypass vulnerability in the Advanced IP Blocker WordPress plugin enables unauthenticated attackers to brute-force MFA tokens and achieve complete site takeover via reusable nonces and lack of rate limiting.","title":"Authentication Bypass in Advanced IP Blocker WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-advanced-ip-blocker-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Advanced IP Blocker (\u003c= 8.13.13)","version":"https://jsonfeed.org/version/1.1"}