目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-104732— Advanced IP Blocker <=8.13.13 未认证绕过两步验证漏洞

一分钟漏洞结论

影响对象
inilerm Advanced IP Blocker
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WordPress 的 Advanced IP Blocker 插件在 8.13.13 及更早版本中存在身份验证绕过漏洞。该漏洞的成因在于 函数在处理 POST 请求中携带的 以进行第二步的 TOTP(一次性密码)验证时,未通过临时数据(transient)、会话标记或类似机制在服务端检查请求者是否已成功完成第一步的密码认证。 此外,该函数中的一个错误分支会无条件地生成一个新的 非ce(nonce),并通过 响应头将其发送给任何未认证的调用者。随后, 函数会在 HTML 中渲染一个有效的 nonce。这些 nonc

CVSS 9.8 · Critical
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-104732 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler
来源: CVE Program / CVE List V5
Vulnerability Description
The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compounding this, an error branch in the function unconditionally mints a fresh `advaipbl-2fa-interim-{user_id}` nonce and delivers it in a `Location` header to any unauthenticated caller, after which `display_2fa_login_form_step_2()` renders a valid `advaipbl-2fa-verify-{user_id}` nonce in HTML — both nonces computed against a fixed `uid=0` empty-session context and therefore fully reusable by the attacker across subsequent requests. This makes it possible for unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators, by brute-forcing an unthrottled 6-digit TOTP code (no attempt counter, no account lockout, and no `wp_login_failed` firing) and receiving a fully authenticated session cookie via `wp_set_auth_cookie` without ever supplying the account password, resulting in complete site takeover. Exploitation requires only a known `user_id` for an account that has the plugin's 2FA feature enabled.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
inilerm Advanced IP Blocker 0 ~ 8.13.13 -

二、漏洞 CVE-2026-104732 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-104732 的情报信息

请登录查看更多情报信息。

CVE-2026-104732 其他参考 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104732

暂无评论


发表评论