What is XML-RPC?
xmlrpc.php is a legacy feature in WordPress designed to allow external applications (like the WordPress mobile app) to interact with your site. However, with the introduction of the WordPress REST API, XML-RPC is largely obsolete.
The Security Risk
Attackers love XML-RPC because of a feature called system.multicall. This allows them to try hundreds of passwords in a single HTTP request, bypassing traditional login limiters and making brute-force attacks incredibly fast and efficient. It's also frequently used in DDoS amplification attacks.
Need immediate help?
If your site is currently hacked or showing warnings, our incident response team can help right now.
How to Disable It
Unless you explicitly rely on a legacy application that requires it, you should disable XML-RPC. You can do this easily within the Nexura Security dashboard, or by adding a block rule to your .htaccess or Nginx configuration.
Upgrade to Nexura Pro
Get enterprise-grade protection. Block zero-day exploits, advanced malware, and brute-force attacks instantly.
LIMITED TIME LAUNCH OFFER
