CVE-2026-104732: Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler

Published Oct 10, 2026
·
Updated

The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because handleloginaction() performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed userid; compounding this, an error branch in the function unconditionally mints a fresh advaipbl-2fa-interim-{userid} nonce and delivers it in a Location header to any unauthenticated caller, after which display2faloginformstep2() renders a valid advaipbl-2fa-verify-{userid} nonce in HTML — both nonces computed against a fixed uid=0 empty-session context and therefore fully reusable by the attacker across subsequent requests. This makes it possible for unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators, by brute-forcing an unthrottled 6-digit TOTP code (no attempt counter, no account lockout, and no wploginfailed firing) and receiving a fully authenticated session cookie via wpsetauthcookie without ever supplying the account password, resulting in complete site takeover. Exploitation requires only a known userid for an account that has the plugin's 2FA feature enabled.

Affected Software

1 affected component
Advanced IP Blocker Advanced IP Blocker<=8.13.13

Event History

Oct 10, 2026
CVE Published
via MITRE·03:26 AM
Data Sourced
via MITRE·03:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker can target accounts with two-factor authentication enabled, including administrator accounts. No existing WordPress account or prior password authentication is required.

2

What does an attacker need to bypass an account?

The attacker needs the target account's user ID and a valid six-digit TOTP value. The affected login flow exposes reusable nonces to unauthenticated callers and permits unlimited TOTP guesses without throttling, lockout, or failed-login events.

3

Are standard protective controls likely to detect repeated attempts?

The vulnerable flow has no attempt counter or account lockout, and it does not trigger wp_login_failed. Repeated TOTP guessing may therefore not be visible through controls that rely on WordPress failed-login events.

4

What is the impact of successful exploitation?

Successful exploitation creates a fully authenticated session cookie for the targeted user through wp_set_auth_cookie. An attacker who targets a 2FA-enabled administrator can gain administrator-level access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203