Wordpress Alert: XML-RPC login abuse
Repeated authentication attempts arrive through XML-RPC on a site that exposes it. Attackers may test credentials through a second login surface.
What it looks like
Repeated authentication attempts arrive through XML-RPC on a site that exposes it.
Why it matters
Attackers may test credentials through a second login surface.
What to check
Review XML-RPC access logs and restrict the feature if the site does not need it.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress brute-force guidance, WordPress hardening guide.
- Categories: WordPress
- Tags: #WordPress Security, #Authentication