High severity Vulnerability

Exposed XML-RPC Endpoint

The WordPress xmlrpc.php endpoint is reachable, enabling brute force amplification and remote pingback abuse.

Overview

XML-RPC lets one HTTP request carry hundreds of system.multicall auth attempts, so a single connection becomes a password-spraying amplifier that defeats simple rate limiting.\nThe pingback.ping method also makes the server issue outbound requests, which fuels DDoS reflection and internal port scanning.\nMost sites do not need it: disable the endpoint unless a legacy integration genuinely depends on it.

Indicators of Compromise

Signals that suggest this is present on a system.

  • POST /xmlrpc.php returning a methods list
  • system.multicall accepted
  • Unsolicited pingback notifications

Controls that stop it

  • Patch Promptly and Continuously

    Maintain an inventory of every framework, plugin and library you run, subscribe to their advisories, and apply fixes on a defined SLA measured in days rather than months. Prioritise anything reachable from the internet or already exploited in the wild. Automate the process so patching does not depend on someone remembering to do it.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used