Impact
The Advanced IP Blocker plugin allows an attacker to bypass authentication by exploiting a missing server‑side check for step‑1 login before processing the step‑2 TOTP verification. An unauthenticated user can request the 2FA step‑2 view, receive a valid nonce, and then brute‑force the 6‑digit time‑based OTP without any throttling, lockout, or login failure event. Successful brute‑force yields a fully authenticated WordPress session cookie, giving the attacker full administrative control. The flaw is a classic use of CWE‑287: authentication bypass.
Affected Systems
The vulnerability affects the WordPress plugin Advanced IP Blocker from vendor inilerm, versions up to and including 8.13.13. All WordPress sites that have any account with the plugin’s 2FA feature enabled are impacted.
Risk and Exploitability
With a CVSS score of 9.8 this flaw is classified as critical. No EPSS score is available, but the absence of any rate‑limiting or account lockout mechanisms means exploitation is straightforward once the attacker has a known user ID. The vulnerability is not listed in the CISA KEV catalog, yet the impact—complete control of the site—demands urgent remediation. The likely attack vector is a remote network request to the plugin’s login handlers, making it exploitable over any public site that hosts Advanced IP Blocker with 2FA enabled.
OpenCVE Enrichment