Quantcast
Channel: WordPress.org Forums » [Wordfence Security - Firewall, Malware Scan, and Login Security] Support
Viewing all articles
Browse latest Browse all 33077

Andrew Nacin on "[Plugin: Wordfence Security] Wordfence and XML-RPC"

$
0
0

This is unfortunately an improper fix and has no tangible benefit for WordPress users.

The changelog says "Disable XML-RPC in WordPress to prevent your site from being used as a drone in a DDoS attack." The problem is this "attack" affects pingbacks. But the fix actually disables everything in XML-RPC except pingbacks, thus breaking mobile apps and anything else relying on XML-RPC, but allowing pingbacks through.

If you want to disable pingbacks, then disable pingbacks. Don't do this. Or don't do anything, as these attacks are not particularly effective and more recent versions of WordPress and Akismet both pass along better information when verifying pingbacks; and Akismet additionally detects abuse.


Viewing all articles
Browse latest Browse all 33077

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>