Disable WordPress XML-RPC
tech-wp-xmlrpc
XML-RPC lets one request try hundreds of passwords through system.multicall, and can be abused for pingback floods. Disable it unless you need it.
Why this matters
XML-RPC is enabled on your WordPress site. It lets an attacker try hundreds of passwords in a single request (system.multicall brute-force) and can be abused for pingback DDoS.
Web servers
Frameworks
Nginx
- 1 Block xmlrpc.php at the web server level
nginx
location = /xmlrpc.php {
deny all;
return 403;
}Does your app still have this?
Scan your domain