<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Advanced IP Blocker (&lt;= 8.13.13) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/advanced-ip-blocker--8.13.13/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:33:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/advanced-ip-blocker--8.13.13/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Advanced IP Blocker WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-advanced-ip-blocker-auth-bypass/</link><pubDate>Sat, 10 Oct 2026 05:33:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-advanced-ip-blocker-auth-bypass/</guid><description>An authentication bypass vulnerability in the Advanced IP Blocker WordPress plugin enables unauthenticated attackers to brute-force MFA tokens and achieve complete site takeover via reusable nonces and lack of rate limiting.</description><content:encoded><![CDATA[<p>The Advanced IP Blocker plugin for WordPress is vulnerable to an authentication bypass in all versions up to and including 8.13.13. The vulnerability, tracked as CVE-2026-104732, exists because the <code>handle_login_action()</code> function fails to perform server-side validation that a user has successfully completed password authentication before processing step-two TOTP submissions.</p>
<p>The plugin generates authentication nonces (<code>advaipbl-2fa-interim-{user_id}</code> and <code>advaipbl-2fa-verify-{user_id}</code>) based on a fixed, empty-session context, making them fully reusable by an attacker. Furthermore, the 2FA verification endpoint lacks rate limiting, account lockout mechanisms, and does not fire standard <code>wp_login_failed</code> hooks. An unauthenticated attacker knowing a valid user ID can leverage these flaws to brute-force a 6-digit TOTP code and obtain a valid authenticated session cookie via <code>wp_set_auth_cookie</code>. This flaw allows for full site takeover, including administrator accounts, without ever requiring the account password.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full unauthorized access to the WordPress environment as the targeted user. If an administrator account is targeted, the attacker gains complete control over the site, allowing for the execution of arbitrary code, data exfiltration, and persistence. Given the lack of rate limiting and logging on the 2FA verification process, attacks may remain undetected until the compromise is already complete.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Advanced IP Blocker plugin to the latest version immediately once a patch is released to mitigate CVE-2026-104732.</li>
<li>Disable the 2FA feature of the Advanced IP Blocker plugin if immediate updating is not possible, and rely on standard WordPress authentication or alternative, patched MFA providers.</li>
<li>Review web server access logs for repeated POST requests to the plugin's login endpoint targeting specific user IDs.</li>
<li>Monitor for unauthorized administrative sessions or modifications to user account privileges.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-vulnerability</category><category>wordpress</category><category>authentication-bypass</category></item></channel></rss>