WordPress: XML-RPC server accepts POST requests only (xmlrpc.php)
You opened xmlrpc.php in a browser (GET) — it’s an API endpoint, not a page. Heavy POST traffic to it usually means brute-force bots.
Seen on:
WordPress
Meaning
XML-RPC serves old apps/Jetpack/pingbacks. Bots abuse it for password guessing (system.multicall) and DDoS pingbacks. If you don’t need it, block it.
Common causes
- Visiting xmlrpc.php directly (expected message)
- Bot traffic hammering xmlrpc.php
- Jetpack/mobile app requiring it
⚡ Quick fix
- Ignore the message if you opened it in a browser
- Block xmlrpc.php at the web server if unused
- Use security plugins to limit XML-RPC
Detailed fix by platform
Apache
- apache
<Files xmlrpc.php> Require all denied </Files>
Nginx
location = /xmlrpc.php { deny all; }
How to diagnose
- Traffic — Requests to xmlrpc.php in access logs
- Usage — Jetpack/app needs it?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in WordPress
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026