security / cms & plugins / xml-rpc
CMS & plugins

XML-RPC

XML-RPC is an older WordPress interface that, if left enabled and unused, can be abused for brute-force and amplification attacks.

Severity if missing
Medium
Category
CMS & plugins
Standard
OWASP

What it is

XML-RPC is a remote interface that predates the modern WordPress REST API. It let external applications interact with a site — posting content, fetching data — through a single endpoint at /xmlrpc.php.

Most modern setups no longer need it, but it's often left enabled by default, quietly offering attackers a useful entry point.

Why it matters

XML-RPC has two well-known abuses. Its system.multicall method lets an attacker try many password combinations in a single request, making brute-force attacks far more efficient. And its pingback feature can be used to bounce attacks off your site against others. If you don't use XML-RPC, disabling it removes both risks.

The risk
An enabled XML-RPC endpoint can be abused to run efficient password-guessing attacks and to relay attacks against other sites.

How Pentrawl checks it

Pentrawl checks whether /xmlrpc.php is active on your site. If it responds, we flag it as a warning, since it's an interface most sites can safely disable.

How to fix it

If you don't rely on XML-RPC, disable it. A security plugin can turn it off with one setting, or you can block the endpoint at the server level.

Block at server (nginx example)
location = /xmlrpc.php { deny all; return 404; }
Check your domain's XML-RPC in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →