Description
The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compounding this, an error branch in the function unconditionally mints a fresh `advaipbl-2fa-interim-{user_id}` nonce and delivers it in a `Location` header to any unauthenticated caller, after which `display_2fa_login_form_step_2()` renders a valid `advaipbl-2fa-verify-{user_id}` nonce in HTML — both nonces computed against a fixed `uid=0` empty-session context and therefore fully reusable by the attacker across subsequent requests. This makes it possible for unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators, by brute-forcing an unthrottled 6-digit TOTP code (no attempt counter, no account lockout, and no `wp_login_failed` firing) and receiving a fully authenticated session cookie via `wp_set_auth_cookie` without ever supplying the account password, resulting in complete site takeover. Exploitation requires only a known `user_id` for an account that has the plugin's 2FA feature enabled.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass leading to complete site takeover
Action: Immediate Patch
AI Analysis

Impact

The Advanced IP Blocker plugin allows an attacker to bypass authentication by exploiting a missing server‑side check for step‑1 login before processing the step‑2 TOTP verification. An unauthenticated user can request the 2FA step‑2 view, receive a valid nonce, and then brute‑force the 6‑digit time‑based OTP without any throttling, lockout, or login failure event. Successful brute‑force yields a fully authenticated WordPress session cookie, giving the attacker full administrative control. The flaw is a classic use of CWE‑287: authentication bypass.

Affected Systems

The vulnerability affects the WordPress plugin Advanced IP Blocker from vendor inilerm, versions up to and including 8.13.13. All WordPress sites that have any account with the plugin’s 2FA feature enabled are impacted.

Risk and Exploitability

With a CVSS score of 9.8 this flaw is classified as critical. No EPSS score is available, but the absence of any rate‑limiting or account lockout mechanisms means exploitation is straightforward once the attacker has a known user ID. The vulnerability is not listed in the CISA KEV catalog, yet the impact—complete control of the site—demands urgent remediation. The likely attack vector is a remote network request to the plugin’s login handlers, making it exploitable over any public site that hosts Advanced IP Blocker with 2FA enabled.

Generated by OpenCVE AI on October 10, 2026 at 04:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Advanced IP Blocker to version 8.13.14 or later
  • Temporarily disable the 2FA feature for administrative accounts until the patch is applied
  • Restrict or block unauthenticated access to the plugin’s 2FA endpoints via firewall or WordPress security settings

Generated by OpenCVE AI on October 10, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compounding this, an error branch in the function unconditionally mints a fresh `advaipbl-2fa-interim-{user_id}` nonce and delivers it in a `Location` header to any unauthenticated caller, after which `display_2fa_login_form_step_2()` renders a valid `advaipbl-2fa-verify-{user_id}` nonce in HTML — both nonces computed against a fixed `uid=0` empty-session context and therefore fully reusable by the attacker across subsequent requests. This makes it possible for unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators, by brute-forcing an unthrottled 6-digit TOTP code (no attempt counter, no account lockout, and no `wp_login_failed` firing) and receiving a fully authenticated session cookie via `wp_set_auth_cookie` without ever supplying the account password, resulting in complete site takeover. Exploitation requires only a known `user_id` for an account that has the plugin's 2FA feature enabled.
Title Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T03:26:45.330Z

Reserved: 2026-10-02T11:49:12.681Z

Link: CVE-2026-104732

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T04:18:08.493

Modified: 2026-10-10T04:18:08.493

Link: CVE-2026-104732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:00:15Z

Weaknesses