All fixes

Disable WordPress XML-RPC

tech-wp-xmlrpc

XML-RPC lets one request try hundreds of passwords through system.multicall, and can be abused for pingback floods. Disable it unless you need it.

Why this matters

XML-RPC is enabled on your WordPress site. It lets an attacker try hundreds of passwords in a single request (system.multicall brute-force) and can be abused for pingback DDoS.

Nginx

  1. 1 Block xmlrpc.php at the web server level
nginx
location = /xmlrpc.php {
    deny all;
    return 403;
}

Does your app still have this?

Scan your domain