← Back to blog
CMS Securitywordpress securitywp-adminXML-RPCwordpress vulnerabilities 2026

WordPress Security Vulnerabilities: The 2026 Checklist for Site Owners

WordPress powers 43% of the web and is the most-attacked CMS. XML-RPC, user enumeration, exposed wp-admin, and outdated plugins create a textbook attack surface. Here's exactly what to check and fix.

25 September 2026·9 min read·The Pedro Research Team

Why WordPress Is Every Hacker's Starting Point

When an attacker targets a domain, the first three questions are: Is it WordPress? Which plugins? Which theme?

WordPress powers 43% of all websites. That market share means every vulnerability gets exploited at scale. A single WordPress plugin with a security flaw can expose millions of sites simultaneously.

We've assessed dozens of WordPress sites as part of broader security assessments. The same issues appear on nearly every one.

The WordPress Vulnerability Checklist

1. XML-RPC — Disable It

XML-RPC is a legacy API WordPress ships enabled by default. It's rarely needed and frequently abused:

# Test if XML-RPC is accessible

$ curl -s https://yoursite.com/xmlrpc.php

...

# A live response means XML-RPC is enabled

# Attackers use it for brute-force amplification:

# One XML-RPC call can test hundreds of username/password combinations

Fix: Add to nginx or Apache config:
location = /xmlrpc.php {

deny all;

}

2. User Enumeration — Hide Your Usernames

WordPress leaks admin usernames by default through multiple channels.

Author archives: https://yoursite.com/?author=1 redirects to /author/admin/ WP REST API:
$ curl https://yoursite.com/wp-json/wp/v2/users

[{"id":1,"name":"admin","slug":"admin",...}]

Login error messages: "The password you entered for the username admin is incorrect." — this confirms the username exists.

Once an attacker has your admin username, brute-force becomes significantly easier. Fix: disable user enumeration and use generic login error messages.

3. wp-admin Brute Force — Add Rate Limiting

WordPress allows unlimited login attempts by default. Fix: add Limit Login Attempts Reloaded plugin and CAPTCHA to wp-login.php.

4. Debug Mode — Turn It Off in Production

// wp-config.php — this must be false in production

define('WP_DEBUG', true); // exposes file paths, errors, stack traces

define('WP_DEBUG_LOG', true); // /wp-content/debug.log — often public

A live debug.log file can contain database credentials, API keys, and internal server paths. We've found 3GB+ debug log files publicly accessible on production sites.

Check if debug log is public:
$ curl -I https://yoursite.com/wp-content/debug.log

# If you get 200 OK, it's exposed

5. Outdated Plugins — The #1 Entry Point

79% of WordPress compromises happen through vulnerable plugins. Plugins to especially watch: Contact Form 7, Yoast SEO, WooCommerce, Elementor — all large attack surfaces with frequent security updates.

Quick Security Audit (15 minutes)

CheckURL/CommandPass if...
XML-RPC/xmlrpc.phpReturns 403/404
Debug log/wp-content/debug.logReturns 403/404
User enum/?author=1Returns 404
REST users/wp-json/wp/v2/usersReturns error
wp-adminTry 10 wrong passwordsAccount locks

Pedro runs all 99+ of these checks automatically.

Scan your WordPress site →
Take Action

FIND THIS ON YOUR
DOMAIN.

Pedro runs 99+ automated security checks. DNS-verified, results in 60 seconds.