Making WordPress.org


Ignore:
Timestamp:
01/11/2022 12:50:48 AM (3 years ago)
Author:
dd32
Message:

Login: Disable all XML-RPC methods on login.w.org, they aren't used and this might persuade some vulneravility scanners not to waste their time with invalid payloads.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-login/functions.php

    r11409 r11426  
    5656 * Disable the Core Language Selector on wp-login.php.
    5757 */
    58 function wporg_login_disable_lang_switcher() {
    59     add_filter( 'login_display_language_dropdown', '__return_false' );
    60 }
    61 add_action( 'login_init', 'wporg_login_disable_lang_switcher' );
     58add_filter( 'login_display_language_dropdown', '__return_false' );
     59
     60/**
     61 * Disable XML-RPC endpoints.
     62 */
     63add_filter( 'xmlrpc_methods', '__return_empty_array' );
    6264
    6365/**
Note: See TracChangeset for help on using the changeset viewer.