Wordpress Alert: Password spraying against WordPress logins

One or a few common passwords are tried across many accounts. A weak account may be taken over without a large attack volume per user.

What it looks like

One or a few common passwords are tried across many accounts.

Why it matters

A weak account may be taken over without a large attack volume per user.

What to check

Look for distributed failed logins and enforce strong, unique passwords.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress brute-force guidance, OWASP authentication guidance.