Why WordPress Is Every Hacker's Starting Point
When an attacker targets a domain, the first three questions are: Is it WordPress? Which plugins? Which theme?
WordPress powers 43% of all websites. That market share means every vulnerability gets exploited at scale. A single WordPress plugin with a security flaw can expose millions of sites simultaneously.
We've assessed dozens of WordPress sites as part of broader security assessments. The same issues appear on nearly every one.
The WordPress Vulnerability Checklist
1. XML-RPC — Disable It
XML-RPC is a legacy API WordPress ships enabled by default. It's rarely needed and frequently abused:
# Test if XML-RPC is accessible
$ curl -s https://yoursite.com/xmlrpc.php
# A live response means XML-RPC is enabled
# Attackers use it for brute-force amplification:
# One XML-RPC call can test hundreds of username/password combinations
Fix: Add to nginx or Apache config:location = /xmlrpc.php {
deny all;
}
2. User Enumeration — Hide Your Usernames
WordPress leaks admin usernames by default through multiple channels.
Author archives:https://yoursite.com/?author=1 redirects to /author/admin/
WP REST API:
$ curl https://yoursite.com/wp-json/wp/v2/users
[{"id":1,"name":"admin","slug":"admin",...}]
Login error messages: "The password you entered for the username admin is incorrect." — this confirms the username exists.Once an attacker has your admin username, brute-force becomes significantly easier. Fix: disable user enumeration and use generic login error messages.
3. wp-admin Brute Force — Add Rate Limiting
WordPress allows unlimited login attempts by default. Fix: add Limit Login Attempts Reloaded plugin and CAPTCHA to wp-login.php.
4. Debug Mode — Turn It Off in Production
// wp-config.php — this must be false in production
define('WP_DEBUG', true); // exposes file paths, errors, stack traces
define('WP_DEBUG_LOG', true); // /wp-content/debug.log — often public
A live debug.log file can contain database credentials, API keys, and internal server paths. We've found 3GB+ debug log files publicly accessible on production sites.
Check if debug log is public:$ curl -I https://yoursite.com/wp-content/debug.log
# If you get 200 OK, it's exposed
5. Outdated Plugins — The #1 Entry Point
79% of WordPress compromises happen through vulnerable plugins. Plugins to especially watch: Contact Form 7, Yoast SEO, WooCommerce, Elementor — all large attack surfaces with frequent security updates.
Quick Security Audit (15 minutes)
| Check | URL/Command | Pass if... |
| XML-RPC | /xmlrpc.php | Returns 403/404 |
| Debug log | /wp-content/debug.log | Returns 403/404 |
| User enum | /?author=1 | Returns 404 |
| REST users | /wp-json/wp/v2/users | Returns error |
| wp-admin | Try 10 wrong passwords | Account locks |
Pedro runs all 99+ of these checks automatically.
Scan your WordPress site →