Wordpress Alert: XML-RPC login abuse
Repeated authentication attempts arrive through XML-RPC on a site that exposes it. Attackers may test credentials through a second login surface.
Guide tag · 10 matching pages
Repeated authentication attempts arrive through XML-RPC on a site that exposes it. Attackers may test credentials through a second login surface.
A custom reset flow uses predictable, reusable, or long-lived tokens. Someone who obtains or guesses a token may reset another person's password.
A third-party login route accepts a password without enforcing the site's second factor. A stolen password may become sufficient for account access.
An active admin session is reused from another browser or location. The attacker can act as the administrator until the session is revoked.
A session identifier survives the transition from signed-out to signed-in state. A person who knows the identifier may inherit the authenticated session.
One or a few common passwords are tried across many accounts. A weak account may be taken over without a large attack volume per user.
Reset URLs appear in logs, analytics, or unintended messages. Anyone with a valid link may take over the account before it expires.
A WordPress application password appears in logs, backups, or a public repository. An external client may gain API access with that credential.
Many login attempts reuse passwords stolen from other services. A reused administrator password may give an attacker dashboard access.
Login or reset screens reveal whether an email address has an account. Attackers can build a target list for password attacks.