XML-RPC server accepts POST requests only 📝 WordPress

WordPress: XML-RPC server accepts POST requests only (xmlrpc.php)

You opened xmlrpc.php in a browser (GET) — it’s an API endpoint, not a page. Heavy POST traffic to it usually means brute-force bots.

Seen on: WordPress

Meaning

XML-RPC serves old apps/Jetpack/pingbacks. Bots abuse it for password guessing (system.multicall) and DDoS pingbacks. If you don’t need it, block it.

Common causes

  • Visiting xmlrpc.php directly (expected message)
  • Bot traffic hammering xmlrpc.php
  • Jetpack/mobile app requiring it

⚡ Quick fix

  1. Ignore the message if you opened it in a browser
  2. Block xmlrpc.php at the web server if unused
  3. Use security plugins to limit XML-RPC

Detailed fix by platform

Apache

  1. apache
    <Files xmlrpc.php>
      Require all denied
    </Files>

Nginx

  1. location = /xmlrpc.php { deny all; }

How to diagnose

  1. Traffic — Requests to xmlrpc.php in access logs
  2. Usage — Jetpack/app needs it?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.