CVE-2026-104732: Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler
The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because handleloginaction() performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed userid; compounding this, an error branch in the function unconditionally mints a fresh advaipbl-2fa-interim-{userid} nonce and delivers it in a Location header to any unauthenticated caller, after which display2faloginformstep2() renders a valid advaipbl-2fa-verify-{userid} nonce in HTML — both nonces computed against a fixed uid=0 empty-session context and therefore fully reusable by the attacker across subsequent requests. This makes it possible for unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators, by brute-forcing an unthrottled 6-digit TOTP code (no attempt counter, no account lockout, and no wploginfailed firing) and receiving a fully authenticated session cookie via wpsetauthcookie without ever supplying the account password, resulting in complete site takeover. Exploitation requires only a known userid for an account that has the plugin's 2FA feature enabled.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker can target accounts with two-factor authentication enabled, including administrator accounts. No existing WordPress account or prior password authentication is required.
What does an attacker need to bypass an account?
The attacker needs the target account's user ID and a valid six-digit TOTP value. The affected login flow exposes reusable nonces to unauthenticated callers and permits unlimited TOTP guesses without throttling, lockout, or failed-login events.
Are standard protective controls likely to detect repeated attempts?
The vulnerable flow has no attempt counter or account lockout, and it does not trigger wp_login_failed. Repeated TOTP guessing may therefore not be visible through controls that rely on WordPress failed-login events.
What is the impact of successful exploitation?
Successful exploitation creates a fully authenticated session cookie for the targeted user through wp_set_auth_cookie. An attacker who targets a 2FA-enabled administrator can gain administrator-level access.