WordPress plugins: Advanced IP Blocker 2FA bypass (CVE-2026-104732, CVSS 9.8) lets unauthenticated attackers log in as any 2FA-enabled user including admins; Blocksy Companion (300,000+ sites, CVE-2026-107645, 9.1) and Advanced Form Integration (CVE-2026-104797, 8.1) also fixed — update to 8.13.14, 2.1.59 and 2.10.0
Wordfence, acting as CVE numbering authority, disclosed three unauthenticated WordPress plugin flaws on 9 October 2026; the CVE records were published on 10 October. The most severe, CVE-2026-104732 (CVSS 9.8) in Advanced IP Blocker (2,000+ active installs), affects versions up to and including 8.13.13: the plugin's two-factor login handler never checks that a visitor passed the password step before accepting a TOTP code for a POSTed user_id, an error path hands any caller a reusable nonce, and TOTP guesses were not rate-limited, counted or logged, so an attacker can brute-force the six-digit code for any 2FA-enabled account, including administrators, and receive a fully authenticated session without the password. The developer's changelog for 8.13.14 lists a critical fix for an authentication bypass in the 2FA login flow plus a lockout after five failed 2FA attempts; 8.13.15 (9 October) adds configurable 2FA lockout settings. CVE-2026-107645 (CVSS 9.1) affects Blocksy Companion up to 2.1.58, the companion plugin for the Blocksy theme with more than 300,000 active installs: on sites that also run WooCommerce with the Dokan marketplace plugin, its account-registration AJAX handler turns off Dokan's nonce check and trusts an attacker-supplied role, letting unauthenticated visitors create and be logged in as a Dokan seller (vendor) account even where vendor sign-up is switched off. Blocksy Companion 2.1.59 (8 October) fixes it ('Account modal – respect Dokan vendor registration setting'). CVE-2026-104797 (CVSS 8.1, high attack complexity) affects Advanced Form Integration up to 2.9.0 (9,000+ installs): where an administrator has mapped a public Contact Form 7 form to the Ultimate Member 'Update Profile Field' action, an unauthenticated visitor can set any user's password, including an administrator's, and take over the site; the CVE record's fix reference is the change to 2.10.0. No exploitation reported. Primary: CVE records (Wordfence CNA); vendor: plugin changelogs on WordPress.org.
- Product
- WordPress plugins: Advanced IP Blocker (inilerm); Blocksy Companion (CreativeThemes); Advanced Form Integration — Connect Forms to 300+ Apps (nasirahmed)
- Versions
- Advanced IP Blocker 8.13.13 and earlier; Blocksy Companion 2.1.58 and earlier; Advanced Form Integration 2.9.0 and earlier
- CVSS
- (CVE-2026-104732); 9.1 (CVE-2026-107645); 8.1 (CVE-2026-104797) — CVSS 3.1, Wordfence
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Update Advanced IP Blocker to 8.13.14 or later (8.13.15 current), Blocksy Companion to 2.1.59 or later and Advanced Form Integration to 2.10.0 or later. Advanced IP Blocker sites: review recent administrator logins and sessions, since failed 2FA guesses were not logged before the fix. Blocksy plus Dokan sites: look for unexpected seller accounts created since registration. Advanced Form Integration sites: check Contact Form 7 to Ultimate Member mappings that take user fields from public forms, and reset admin passwords if any such mapping existed.
Primary: CVE-2026-104732 — Advanced IP Blocker <= 8.13.13 unauthenticated 2FA authentication bypass (Wordfence CNA, published 10 Oct 2026); see also CVE-2026-107645 and CVE-2026-104797 · Vendor: Advanced IP Blocker changelog — 8.13.14 'Security (Critical): Fixed an Authentication Bypass vulnerability in the 2FA login flow' · CVE: CVE-2026-104732, CVE-2026-107645, CVE-2026-104797 · Blocksy Companion changelog — 2.1.59 (8 Oct 2026): respect Dokan vendor registration setting
