• Resolved viche

    (@viche)


    Hi!

    On several sites where V5.3.10 auto updated the plugin triggered a lot of email says users (fake) har been blocked from site when trying to brute force.

Viewing 10 replies - 1 through 10 (of 10 total)
  • Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @viche,

    Can you please cross-check audit logs from WP security > Dashboard > Audit logs that do have the Failed login? type events recorded “All events” have filter for it.

    Regards

    Thread Starter viche

    (@viche)

    Hi!

    Around ten of these per hour.

    27 mars, 2025 09:10
    Delete
    warning admin 103.219.70.114
    Lock IP | Blacklist IP
    Failed login
    Failed login attempt with a unknown username: admin
    Show trace

    Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @viche,

    You may check the details of that IP and if it is not related to your server etc.. and if from another country you may directly Blacklist that IP.

    Regards

    Thread Starter viche

    (@viche)

    But hey wait.

    This version is released and several users reports different errors.

    I did not get this mails before 5 3 10

    Should we move away from your plugin?

    Thread Starter viche

    (@viche)

    Hi!

    For me it says XML-RPC server accepts POST requests only.

    Completely block access to XMLRPC: checked

    Disable pingback functionality from XMLRPC:

    These two settings I have on perhaps 50+ websites and it has worked fine.

    I remember there was a similar error a few years ago with a corrupt update then too.

    Thread Starter viche

    (@viche)

    Disable pingback functionality from XMLRPC: NOT checked.

    sorry

    Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @viche

    URL {site_url}/xmlrpc.php If it shows the blank page with 403 forbidden it should not be an XML RPC call tried to log in and filed an attempt but still the stack trace of failed login need to check if it is xmlrpc.php It might be during the plugin updated only not after that.

    https://snipboard.io/h4eqYd.jpg

    Regards

    Thread Starter viche

    (@viche)

    After updating to 5.4.0 I got 403 instead when visiting xmlrpc.php.

    5.3.8 No emails
    5.3.10 My inbox is crying
    5.4.0 No emails

    Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @viche

    Good that the xmlrpc.php showing 403 due to disabled xml rpc using firewall.

    After the AIOS 5.4.0 update, login lockout emails are not received that seem good news.

    Nothing has been changed for it. I will create an internal ticket to check more details as to why AIOS 5.3.10 has such an issue.

    Regards

    Thread Starter viche

    (@viche)

    Thanks! πŸ™

Viewing 10 replies - 1 through 10 (of 10 total)
  • You must be logged in to reply to this topic.