Back to Intelligence

CVE-2026-104732 and 6 Critical WordPress Plugin CVEs (CVSS 9.8): Detection and Remediation Guide

SA
Security Arsenal Team
October 10, 2026
9 min read

In the last 72 hours, the National Vulnerability Database published seven CRITICAL-severity CVEs affecting WordPress plugins, all network-exploitable and several scoring CVSS 9.8. The headline flaw, CVE-2026-104732, is an authentication bypass in the Advanced IP Blocker plugin — a security plugin, ironically — affecting all versions up to and including 8.13.13. Two additional 9.8-rated flaws were disclosed in Extensions For CF7 (CVE-2026-94589) and 3D Product Configurator for WooCommerce (CVE-2026-103889), alongside four more critical issues: CVE-2026-104803, CVE-2026-107645, CVE-2026-97670, and CVE-2026-104801.

This is a worst-case pattern we see repeatedly in WordPress incident response: unauthenticated, remotely exploitable flaws in widely deployed plugins, on a platform that powers a substantial share of the public internet. If you operate WordPress — especially WooCommerce storefronts — assume these vulnerabilities will be weaponized quickly. WordPress plugin CVEs at 9.8 are historically among the fastest to be mass-scanned and exploited after disclosure.

Technical Analysis

CVE-2026-104732 — Advanced IP Blocker Authentication Bypass (CVSS 9.8)

Affected product: Advanced IP Blocker plugin for WordPress, all versions ≤ 8.13.13.

The vulnerability lives in the plugin's handle_login_action() function. The plugin implements a two-step login flow, but the step-2 handler performs no server-side verification — via transient, session marker, or equivalent — that the requester actually completed step-1 password authentication. In practical terms: an unauthenticated remote attacker can submit a crafted request directly to the step-2 handler and the plugin will process it as if the user had already authenticated.

From a defender's perspective, the attack chain is:

  1. Attacker identifies the plugin's presence (plugin paths, readme files, exposed AJAX actions).
  2. Attacker sends a direct request to the vulnerable handler, skipping the step-1 password check entirely.
  3. The plugin grants the authenticated-state outcome, giving the attacker a foothold that — depending on the plugin's privileged functionality — can be leveraged for administrative access, malicious plugin/theme upload, or configuration tampering.

The deeper concern: a successful authentication bypass on WordPress almost always becomes a web shell, because authenticated admin access enables theme/plugin editor abuse and arbitrary file upload. Expect post-exploitation artifacts in wp-content/uploads/ and unexpected PHP files with recent modification times.

The Remaining Six CVEs

CVEProductCVSSNotes
CVE-2026-94589Extensions For CF7 (Contact Form 7 Database, Conditional Fields and Redirection)9.8Critical, network-exploitable
CVE-2026-1038893D Product Configurator for WooCommerce9.8Critical, network-exploitable; WooCommerce stores are high-value targets
CVE-2026-104803WordPress plugin (per NVD)CriticalDetails pending full NVD enrichment
CVE-2026-107645WordPress plugin (per NVD)CriticalDetails pending full NVD enrichment
CVE-2026-97670WordPress plugin (per NVD)CriticalDetails pending full NVD enrichment
CVE-2026-104801WordPress plugin (per NVD)CriticalDetails pending full NVD enrichment

Exploitation status: At the time of writing, none of these CVEs are confirmed on the CISA Known Exploited Vulnerabilities catalog, and no public in-the-wild exploitation has been confirmed. However, NVD publication of a CVSS 9.8 unauthenticated flaw in a WordPress plugin is reliably followed by scanner activity within days. Treat these as pre-exploitation window vulnerabilities — patch before the PoCs land, not after. Monitor the CISA KEV catalog and the NVD entry for CVE-2026-104732 for status changes.

Detection & Response

Your detection strategy has two layers: (1) identify exploitation attempts against the vulnerable plugin endpoints in web access logs, and (2) catch the near-inevitable post-exploitation behavior — PHP spawning shells and dropped web shells — because you should assume some sites were vulnerable before you patched.

Sigma Rules

YAML
---
title: WordPress Advanced IP Blocker Plugin Exploitation Attempt
id: 3f8a2c71-6b4d-4e19-9c83-5a7d2e1f9b04
status: experimental
description: Detects HTTP requests targeting the Advanced IP Blocker plugin's login handler or plugin paths, consistent with CVE-2026-104732 authentication bypass probing. Requests hitting the plugin's AJAX actions without a preceding legitimate login flow are suspicious.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-104732
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.initial_access
  - attack.t1190
logsource:
  category: webserver
detection:
  selection_uri:
    cs-uri|contains:
      - '/wp-content/plugins/advanced-ip-blocker/'
      - '/wp-admin/admin-ajax.php'
  selection_method:
    cs-method: 'POST'
  condition: selection_uri and selection_method
falsepositives:
  - Legitimate admin-ajax.php usage is extremely common on WordPress; tune by alerting only on POST requests containing plugin-specific action parameters or originating from sources with no prior step-1 authentication in the session
level: high
---
title: Web Server Process Spawning Shell (WordPress Web Shell Post-Exploitation)
id: 9c1e5b42-7d3f-4a28-b654-8e2f1a9c6d07
status: experimental
description: Detects the web server or PHP-FPM process spawning a command shell or system utility — a hallmark of web shell execution following WordPress plugin compromise such as CVE-2026-104732.
references:
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/php-fpm'
      - '/apache2'
      - '/httpd'
      - '/nginx'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/dash'
      - '/curl'
      - '/wget'
      - '/python'
      - '/python3'
      - '/perl'
      - '/nc'
      - '/ncat'
  condition: selection_parent and selection_child
falsepositives:
  - Some backup, cache, or image-processing plugins shell out to system tools; baseline per-host and investigate any php-fpm spawning interactive shells
level: critical

KQL — Microsoft Sentinel

This query hunts WordPress exploitation attempts and post-exploitation web shell behavior across ingested web logs (CommonSecurityLog/CEF or Syslog) and Defender for Endpoint process telemetry if your web servers are onboarded:

KQL — Microsoft Sentinel / Defender
// Layer 1: Exploitation attempts against vulnerable WordPress plugin endpoints
union isfuzzy=true
    (CommonSecurityLog
    | where TimeGenerated > ago(7d)
    | where RequestURL has_any ("advanced-ip-blocker", "extensions-for-cf7", "3d-product-configurator")
        or (RequestURL has "admin-ajax.php" and RequestMethod == "POST")
    | summarize Hits=count(), DistinctURIs=dcount(RequestURL) by SourceIP, RequestURL, RequestMethod, bin(TimeGenerated, 1h)),
    (Syslog
    | where TimeGenerated > ago(7d)
    | where SyslogMessage has_any ("advanced-ip-blocker", "admin-ajax.php") and SyslogMessage has "POST"
    | summarize Hits=count() by HostIP, ProcessName, bin(TimeGenerated, 1h))
| sort by Hits desc;

// Layer 2: Web server processes spawning shells or download tools (post-exploitation)
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where InitiatingProcessFileName has_any ("php-fpm", "php", "apache2", "httpd", "nginx")
| where FileName has_any ("sh", "bash", "dash", "curl", "wget", "nc", "ncat", "python", "python3", "perl")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine, AccountName, InitiatingProcessCommandLine
| sort by TimeGenerated desc;

Velociraptor VQL — Web Shell Hunt

If you suspect compromise, hunt for recently modified or anomalous PHP files in upload directories — the most common web shell landing zone after WordPress plugin exploitation:

VQL — Velociraptor
-- Hunt for recently modified PHP files in WordPress upload and plugin directories
-- Legitimate PHP should rarely appear under wp-content/uploads
SELECT FullPath, Size, Mtime, Atime, Ctime,
       hash(path=FullPath) AS Hash
FROM glob(globs=['/var/www/**/wp-content/uploads/**/*.php',
                 '/var/www/**/wp-content/plugins/**/*.php',
                 '/srv/www/**/wp-content/uploads/**/*.php'])
WHERE Mtime > now() - 604800
   OR FullPath =~ 'wp-content/uploads/.*\\.php$'
ORDER BY Mtime DESC

Remediation / Verification Script

Run this on each WordPress host (or via your configuration management fleet-wide) to inventory the vulnerable plugins, force updates, and flag suspicious PHP in upload directories:

Bash / Shell
#!/bin/bash
# CVE-2026-104732 + related WordPress plugin CVE triage script
# Requires WP-CLI; run as the web root owner or adjust --path per vhost

WP_PATH="/var/www/html"

echo "=== [1] Checking Advanced IP Blocker version (vulnerable: <= 8.13.13) ==="
wp plugin list --path="$WP_PATH" --format=table | grep -iE "advanced-ip-blocker|extensions-for-cf7|3d-product-configurator" || echo "Target plugins not found in this install."

echo "=== [2] Forcing plugin updates ==="
wp plugin update --all --path="$WP_PATH"

echo "=== [3] Verifying core integrity (detect tampered core files) ==="
wp core verify-checksums --path="$WP_PATH"

echo "=== [4] Hunting web shells: PHP files under uploads modified in last 14 days ==="
find "$WP_PATH/wp-content/uploads" -type f -name "*.php" -mtime -14 -ls

echo "=== [5] Audit recently created admin users (post-auth-bypass persistence) ==="
wp user list --role=administrator --path="$WP_PATH" --format=table

echo "=== [6] Reviewing recent failed/anomalous logins from access logs ==="
grep -E "admin-ajax.php|advanced-ip-blocker" /var/log/apache2/access.log /var/log/nginx/access.log 2>/dev/null | tail -n 50

echo "=== Done. Any PHP under uploads or unknown admins = escalate to IR. ==="

Remediation

  1. Patch immediately. Update Advanced IP Blocker to a version newer than 8.13.13 (verify the fixed release against the plugin's WordPress.org changelog and the NVD advisory). Apply the same treatment to Extensions For CF7 and 3D Product Configurator for WooCommerce — pull the fixed versions from the official plugin repository, not third-party mirrors.
  2. Inventory first. Many organizations don't know which plugins run on which sites. Use WP-CLI (wp plugin list) across all vhosts, or your hosting control panel, to build the exposure list before patching. Delete — don't just deactivate — unused plugins; deactivated plugin code is still reachable in some attack paths.
  3. If you cannot patch today: place the affected sites behind a WAF with rules blocking unauthenticated POSTs to the vulnerable plugin's AJAX actions, or temporarily deactivate the plugin. For CVE-2026-104732 specifically, blocking direct requests to the plugin's login handler short-circuits the bypass.
  4. Assume breach on internet-facing installs that were exposed. Run the web shell hunt above, verify core checksums, audit administrator accounts and scheduled cron entries (wp cron event list), and rotate WordPress salts/keys and admin credentials if you find any anomaly.
  5. Harden going forward: disable the theme/plugin editor (define('DISALLOW_FILE_EDIT', true);), block PHP execution in wp-content/uploads/ via web server config, enable auto-updates for plugins, and restrict xmlrpc.php and wp-admin by IP where operationally feasible.
  6. Monitor KEV. None of these are on CISA KEV as of publication — that can change fast. Subscribe to KEV and NVD feeds and treat addition of any of these CVEs as an emergency patch trigger with a CISA-mandated deadline if you're in the federal supply chain.

The window between NVD publication and mass exploitation of critical WordPress plugin flaws is measured in days, not weeks. Patch now, hunt for what may have already happened, and close the plugin hygiene gaps that made you exposable in the first place.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.