What does this usually mean?
XML-RPC can support legitimate integrations, but it is also commonly abused for authentication pressure and amplification-style behavior. The right action depends on whether the site actually needs it.
Guide
XML-RPC being reachable is not automatically a breach, but on many sites it is unnecessary exposure that should be reviewed.
XML-RPC can support legitimate integrations, but it is also commonly abused for authentication pressure and amplification-style behavior. The right action depends on whether the site actually needs it.
XML-RPC can support legitimate integrations, but it is also commonly abused for authentication pressure and amplification-style behavior. The right action depends on whether the site actually needs it.
Confirm whether the site has a legitimate XML-RPC dependency.
Need help checking this on a live store?
If XML-RPC exposure appears alongside other scanner findings, request a Site Rescue Review to decide whether to restrict it and what to check next.