Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

A Look at the New WordPress Brute Force Amplification Attack

Blog post from Cloudflare

Post Details
Company
Date Published
Author
Pasha Kravtsov
Word Count
838
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

A new brute force attack method for WordPress instances has been identified by Sucuri, allowing attackers to try a large number of username and password login combinations in a single HTTP request. This latest technique is harder to detect since it doesn't necessarily flood the server with requests. The vulnerability can be exploited using XML-RPC, which uses XML encoding over HTTP to provide a remote procedure call protocol commonly used for APIs and automated tasks in WordPress instances. CloudFlare paid customers have the option to enable a Web Application Firewall ruleset to stop this new attack method.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.