vulnerability
Published 2026-10-09
Verified 2026-10-10

WordPress plugins: Advanced IP Blocker 2FA bypass (CVE-2026-104732, CVSS 9.8) lets unauthenticated attackers log in as any 2FA-enabled user including admins; Blocksy Companion (300,000+ sites, CVE-2026-107645, 9.1) and Advanced Form Integration (CVE-2026-104797, 8.1) also fixed — update to 8.13.14, 2.1.59 and 2.10.0

Wordfence, acting as CVE numbering authority, disclosed three unauthenticated WordPress plugin flaws on 9 October 2026; the CVE records were published on 10 October. The most severe, CVE-2026-104732 (CVSS 9.8) in Advanced IP Blocker (2,000+ active installs), affects versions up to and including 8.13.13: the plugin's two-factor login handler never checks that a visitor passed the password step before accepting a TOTP code for a POSTed user_id, an error path hands any caller a reusable nonce, and TOTP guesses were not rate-limited, counted or logged, so an attacker can brute-force the six-digit code for any 2FA-enabled account, including administrators, and receive a fully authenticated session without the password. The developer's changelog for 8.13.14 lists a critical fix for an authentication bypass in the 2FA login flow plus a lockout after five failed 2FA attempts; 8.13.15 (9 October) adds configurable 2FA lockout settings. CVE-2026-107645 (CVSS 9.1) affects Blocksy Companion up to 2.1.58, the companion plugin for the Blocksy theme with more than 300,000 active installs: on sites that also run WooCommerce with the Dokan marketplace plugin, its account-registration AJAX handler turns off Dokan's nonce check and trusts an attacker-supplied role, letting unauthenticated visitors create and be logged in as a Dokan seller (vendor) account even where vendor sign-up is switched off. Blocksy Companion 2.1.59 (8 October) fixes it ('Account modal – respect Dokan vendor registration setting'). CVE-2026-104797 (CVSS 8.1, high attack complexity) affects Advanced Form Integration up to 2.9.0 (9,000+ installs): where an administrator has mapped a public Contact Form 7 form to the Ultimate Member 'Update Profile Field' action, an unauthenticated visitor can set any user's password, including an administrator's, and take over the site; the CVE record's fix reference is the change to 2.10.0. No exploitation reported. Primary: CVE records (Wordfence CNA); vendor: plugin changelogs on WordPress.org.

Product
WordPress plugins: Advanced IP Blocker (inilerm); Blocksy Companion (CreativeThemes); Advanced Form Integration — Connect Forms to 300+ Apps (nasirahmed)
Versions
Advanced IP Blocker 8.13.13 and earlier; Blocksy Companion 2.1.58 and earlier; Advanced Form Integration 2.9.0 and earlier
CVSS
(CVE-2026-104732); 9.1 (CVE-2026-107645); 8.1 (CVE-2026-104797) — CVSS 3.1, Wordfence
Exploited in Australia?
unknown
Patch to
Update Advanced IP Blocker to 8.13.14 or later (8.13.15 current), Blocksy Companion to 2.1.59 or later and Advanced Form Integration to 2.10.0 or later. Advanced IP Blocker sites: review recent administrator logins and sessions, since failed 2FA guesses were not logged before the fix. Blocksy plus Dokan sites: look for unexpected seller accounts created since registration. Advanced Form Integration sites: check Contact Form 7 to Ultimate Member mappings that take user fields from public forms, and reset admin passwords if any such mapping existed.

Primary: CVE-2026-104732 — Advanced IP Blocker <= 8.13.13 unauthenticated 2FA authentication bypass (Wordfence CNA, published 10 Oct 2026); see also CVE-2026-107645 and CVE-2026-104797 · Vendor: Advanced IP Blocker changelog — 8.13.14 'Security (Critical): Fixed an Authentication Bypass vulnerability in the 2FA login flow' · CVE: CVE-2026-104732, CVE-2026-107645, CVE-2026-104797 · Blocksy Companion changelog — 2.1.59 (8 Oct 2026): respect Dokan vendor registration setting

vulnerabilities identity