[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foAsr1X6TGNixwutzJPEfELPMtDGgIuapigWMciEPbEY":3,"$fvjlHAEsBqyraZXn9wtJ08DDbCda34SEjW56ZvcJdEHk":161,"$fMn-HRdAiVK4K_Pqq0r4mkd9fa0ePQCgDQ-FXjVh4k9s":166},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":14,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"discovery_status":31,"vulnerabilities":32,"developer":51,"crawl_stats":38,"alternatives":58,"analysis":38,"fingerprints":38},"vampire-character","Vampire Character Manager","2.15","magent","https:\u002F\u002Fprofiles.wordpress.org\u002Fmagent\u002F","\u003Cp>This WordPress plugin is intended to manage vampire character sheets for LARPs and online vampire games.\u003C\u002Fp>\n\u003Cp>Features are:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Online character generation\u003C\u002Fli>\n\u003Cli>Track and assign changes in Experience and other ratings\u003C\u002Fli>\n\u003Cli>Output a PDF character for printing\u003C\u002Fli>\n\u003Cli>Configure character generation rules using templates\u003C\u002Fli>\n\u003Cli>Configure experience point and freebie point costs\u003C\u002Fli>\n\u003Cli>Add\u002FEdit character and source data\u003C\u002Fli>\n\u003Cli>Storyteller approval of XP spends and character background updates\u003C\u002Fli>\n\u003Cli>Display area map using Google API\u003C\u002Fli>\n\u003Cli>Automatically list active characters and what their status is\u003C\u002Fli>\n\u003Cli>Get reports (CSV and PDF) such as character activity\u003C\u002Fli>\n\u003Cli>In-character Private Messaging system\u003C\u002Fli>\n\u003Cli>Send a newsletter with Experience point totals\u003C\u002Fli>\n\u003Cli>Can send notification emails via Mail or SMTP\u003C\u002Fli>\n\u003Cli>Export and import the database to create and restore backups\u003C\u002Fli>\n\u003Cli>(new) Custom WordPress REST API endpoints to allow integration with other applications\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Shortcodes\u003C\u002Fh3>\n\u003Ch4>background_table\u003C\u002Fh4>\n\u003Cp>Display a list of characters with a specific Background. Defaults are highlighted.\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>background – which background to list (defaults to Status)\u003C\u002Fli>\n\u003Cli>liststatus – only list characters with a specific character status (\u003Cem>Alive\u003C\u002Fem>, Missing, Dead, Staked, Torpor)\u003C\u002Fli>\n\u003Cli>level – only list characters with a specific level of background (\u003Cem>all\u003C\u002Fem>, displayzeros, )\u003C\u002Fli>\n\u003Cli>domain – only list characters in a specific domain (\u003Cem>home\u003C\u002Fem>, )\u003C\u002Fli>\n\u003Cli>heading – show or hide table headings (\u003Cem>1\u003C\u002Fem>, 0)\u003C\u002Fli>\n\u003Cli>columns – define which columns to display in a comma-separated list (\u003Cem>level, character, player, clan, domain, background, sector, comment, level, office\u003C\u002Fem>, sect)\u003C\u002Fli>\n\u003Cli>matchtype – advanced filtering options. Specify what kind of match to make:\n\u003Cul>\n\u003Cli>sector – list backgrounds that match the specified sector\u003C\u002Fli>\n\u003Cli>comment – list backgrounds that match the specified comment\u002Fspecialisation\u003C\u002Fli>\n\u003Cli>characteristic – list backgrounds that match a characteristic from a character\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>match – use with matchtype. Specify what to filter on\u002Fmatch to\n\u003Cul>\n\u003Cli>loggedinclan – list matches with the clan of the logged in user\u003C\u002Fli>\n\u003Cli>loggedinsect – list matches with the sect of the logged in user\u003C\u002Fli>\n\u003Cli> – list matches the selected level\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Examples:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Display all active characters in the current domain\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[background_table level=displayzeros columns=”character,clan,office”]\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Display all dead characters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[background_table columns=”character,clan,player” level=displayzeros court=”” liststatus=Dead]\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Display a list of vampires with Clan Prestige in the same clan as you (logged in)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[background_table columns=”level,character,clan” match=loggedinclan matchtype=comment background=”Clan Prestige”]\u003C\u002Fp>\n\u003Cp>Note that for this to work, on the character sheet the character must have the clan name entered\u003Cbr \u002F>\ninto the comment\u002Fspecialisation box for the background.\u003C\u002Fp>\n\u003Ch4>character_detail_block\u003C\u002Fh4>\n\u003Cp>Display character information for the logged in character.\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>group – Sub-group of information to display\n\u003Cul>\n\u003Cli>char_name – character name\u003C\u002Fli>\n\u003Cli>domain – domain of residence\u003C\u002Fli>\n\u003Cli>pub_clan – public clan, i.e. the clan that they publicly admit to being a member of\u003C\u002Fli>\n\u003Cli>priv_clan – private clan, i.e the clan they actually are\u003C\u002Fli>\n\u003Cli>sire – Name of Sire\u003C\u002Fli>\n\u003Cli>gen – generation\u003C\u002Fli>\n\u003Cli>blood_per_round – number of blood points that can be spent per round\u003C\u002Fli>\n\u003Cli>path_name – Path of Enlightenment name\u003C\u002Fli>\n\u003Cli>path_value – Level of Path of Enlightenment\u003C\u002Fli>\n\u003Cli>bloodpool – Size of the bloodpool\u003C\u002Fli>\n\u003Cli>nature – Character nature (if used)\u003C\u002Fli>\n\u003Cli>demeanour – Character demeanour (if used, and note UK spelling)\u003C\u002Fli>\n\u003Cli>date_of_birth – Date of Birth\u003C\u002Fli>\n\u003Cli>date_of_embrace – Date of Embrace\u003C\u002Fli>\n\u003Cli>status – Character Status (e.g. Alive, Dead)\u003C\u002Fli>\n\u003Cli>status_comment – Comment on character status\u003C\u002Fli>\n\u003Cli>last_updated – date character was last updated (e.g. XP spent)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>“Your character was last updated on [character_detail_block group=last_updated].”\u003C\u002Fp>\n\u003Ch4>character_offices_block\u003C\u002Fh4>\n\u003Cp>Display the Offices of the logged-in character\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[character_offices_block]\u003C\u002Fp>\n\u003Ch4>character_road_or_path_table\u003C\u002Fh4>\n\u003Cp>Display Path of Enlightenment changes for the logged-in character\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>group – Sub-group of information to display\n\u003Cul>\n\u003Cli>total – current path level\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[character_road_or_path_table]\u003C\u002Fp>\n\u003Cp>“Your path rating is [character_road_or_path_table group=total].”\u003C\u002Fp>\n\u003Ch4>character_temp_stats\u003C\u002Fh4>\n\u003Cp>Show information on Willpower or Blood spends\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>showtable – show changes in a table (\u003Cem>0\u003C\u002Fem>, 1)\u003C\u002Fli>\n\u003Cli>limit – limit how many rows in the table (defaults to 5)\u003C\u002Fli>\n\u003Cli>stat – specify which stat to display (\u003Cem>Willpower\u003C\u002Fem>, Blood)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[character_temp_stats showtable=1 limit=10 stat=Blood]\u003C\u002Fp>\n\u003Ch4>character_xp_table\u003C\u002Fh4>\n\u003Cp>List the XP spends and assignments for the logged in character\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>maxrecords – limit how many rows in the table (defaults to 20)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[character_xp_table maxrecords=100]\u003C\u002Fp>\n\u003Ch4>feeding_map\u003C\u002Fh4>\n\u003Cp>Display the domain\u002Ffeeding map.  Domains and who owns them are defined in the Data Tables\u003Cbr \u002F>\nadmin section.  You will need a valid Google API code for this feature to work.\u003Cbr \u002F>\n(https:\u002F\u002Fdevelopers.google.com\u002Fmaps\u002Fdocumentation\u002Fjavascript\u002Ftutorial)\u003C\u002Fp>\n\u003Cp>[feeding_map]\u003C\u002Fp>\n\u003Ch4>merit_table\u003C\u002Fh4>\n\u003Cp>Displays a table of characters with a specific Merit or Flaw.\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>merit – Merit or Flaw name to list (Default is “Clan Friendship”)\u003C\u002Fli>\n\u003Cli>match – add a filter to the list\n\u003Cul>\n\u003Cli>loggedinclan – Comment\u002Fspecialisation must match that of the clan of the logged in user\u003C\u002Fli>\n\u003Cli> – match the specified value\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>liststatus – only list characters with a specific character status (\u003Cem>Alive\u003C\u002Fem>, Missing, Dead, Staked, Torpor)\u003C\u002Fli>\n\u003Cli>heading – show or hide table headings (\u003Cem>1\u003C\u002Fem>, 0)\u003C\u002Fli>\n\u003Cli>domain – only list characters in a specific domain (\u003Cem>home\u003C\u002Fem>, )\u003C\u002Fli>\n\u003Cli>columns – define which columns to display in a comma-separated list (\u003Cem>level, character, player, clan, domain, merit, comment, level\u003C\u002Fem>, sect)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For example, display a list of character with Enmity towards your clan\u003C\u002Fp>\n\u003Cp>[merit_table merit=’Clan Enmity’ match=loggedinclan]\u003C\u002Fp>\n\u003Ch4>office_block\u003C\u002Fh4>\n\u003Cp>List all the characters with an office or position of power\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>domain – domain character is an official in\u003C\u002Fli>\n\u003Cli>office – specific office to display\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>“The ruler of Glasgow is [office_block domain=Glasgow office=Prince].”\u003C\u002Fp>\n\u003Ch4>spend_button\u003C\u002Fh4>\n\u003Cp>Displays a button for characters to click to spend Willpower or Bloodpoints.\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>character – WordPress login name of character to be ‘logged in’ as (ST\u002Fadmin only)\u003C\u002Fli>\n\u003Cli>stat – which Stat the button is for:\n\u003Cul>\n\u003Cli>Willpower\u003C\u002Fli>\n\u003Cli>Blood\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>inbox_summary\u003C\u002Fh4>\n\u003Cp>List the last x private messages.\u003C\u002Fp>\n\u003Cp>Options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>list – define what messages to display\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>[inbox_summary list=5]\u003C\u002Fp>\n\u003Ch3>Widgets\u003C\u002Fh3>\n\u003Ch4>Character Login Widget\u003C\u002Fh4>\n\u003Cp>Displays useful links:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Login\u002Flogout\u003C\u002Fli>\n\u003Cli>Character Sheet\u003C\u002Fli>\n\u003Cli>Character Profile\u003C\u002Fli>\n\u003Cli>Spend Experience\u003C\u002Fli>\n\u003Cli>Character Inbox (x unread)\u003C\u002Fli>\n\u003Cli>Addressbook\u003C\u002Fli>\n\u003Cli>Contact Details\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Character Background Widget\u003C\u002Fh4>\n\u003Cp>Displays how much of the character background has been completed.\u003C\u002Fp>\n\u003Ch4>Sunset\u002FSunrise Times\u003C\u002Fh4>\n\u003Cp>Display the times of sunset and sunrise.\u003C\u002Fp>\n\u003Ch4>WordPress REST API Endpoints\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cem>\u002Fwp-json\u002Fvampire-character\u002Fv1\u002Fcharacter\u003C\u002Fem> : return a list of the active characters (Storyteller only)\u003C\u002Fli>\n\u003Cli>\u003Cem>\u002Fwp-json\u002Fvampire-character\u002Fv1\u002Fcharacter\u002F\u003C\u002Fem> : return character information by character ID (Storyteller only)\u003C\u002Fli>\n\u003Cli>\u003Cem>\u002Fwp-json\u002Fvampire-character\u002Fv1\u002Fcharacter\u002Fwpid&wordpress_id=\u003C\u002Fem> : return character information by wordpress username\u003C\u002Fli>\n\u003Cli>\u003Cem>\u002Fwp-json\u002Fvampire-character\u002Fv1\u002Fcharacter\u002Fme\u003C\u002Fem> : return character information for logged-in user\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Template Tags\u003C\u002Fh3>\n\u003Cp>None\u003C\u002Fp>\n","For managing characters for LARPs and online vampire games.",10,4561,100,1,"2026-06-27T13:06:00.000Z","7.0.2","6.2","8.1",[20,21,22,23,24],"character-generation","larp","lrp","rpg","vampire","http:\u002F\u002Fplugin.gvlarp.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.15.zip",99,0,"2025-01-16 00:00:00","2026-07-22T17:31:50.256Z","no_bundle",[33],{"id":34,"url_slug":35,"title":36,"description":37,"plugin_slug":4,"theme_slug":38,"affected_versions":39,"patched_in_version":40,"severity":41,"cvss_score":42,"cvss_vector":43,"vuln_type":44,"published_date":29,"updated_date":45,"references":46,"days_to_patch":48,"patch_diff_files":49,"patch_trac_url":38,"research_status":38,"research_verified":50,"research_rounds_completed":28,"research_plan":38,"research_summary":38,"research_vulnerable_code":38,"research_fix_diff":38,"research_exploit_outline":38,"research_model_used":38,"research_started_at":38,"research_completed_at":38,"research_error":38,"poc_status":38,"poc_video_id":38,"poc_summary":38,"poc_steps":38,"poc_tested_at":38,"poc_wp_version":38,"poc_php_version":38,"poc_playwright_script":38,"poc_exploit_code":38,"poc_has_trace":50,"poc_model_used":38,"poc_verification_depth":38},"CVE-2025-23465","vampire-character-manager-reflected-cross-site-scripting","Vampire Character Manager \u003C= 2.13 - Reflected Cross-Site Scripting","The Vampire Character Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",null,"\u003C=2.13","2.14","medium",6.1,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2026-06-23 17:32:32",[47],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fa1f153bb-87b0-4dc7-b014-776ab20ad8c3?source=api-prod",524,[],false,{"slug":7,"display_name":52,"profile_url":8,"plugin_count":53,"total_installs":54,"avg_security_score":55,"avg_patch_time_days":48,"trust_score":56,"computed_at":57},"Magenta Cuda",8,60,91,73,"2026-08-29T11:20:29.783Z",[59,78,98,120,140],{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":69,"num_ratings":70,"last_updated":71,"tested_up_to":16,"requires_at_least":72,"requires_php":73,"tags":74,"homepage":76,"download_link":77,"security_score":13,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"disable-xml-rpc","Disable XML-RPC","1.0.1","Phil Erb","https:\u002F\u002Fprofiles.wordpress.org\u002Fphilerb\u002F","\u003Cp>Pretty simply, this plugin uses the built-in WordPress filter “xmlrpc_enabled” to disable the XML-RPC API on a WordPress site running 3.5 or above.\u003C\u002Fp>\n\u003Cp>Beginning in 3.5, XML-RPC is enabled by default. Additionally, the option to disable\u002Fenable XML-RPC was removed. For various reasons, site owners may wish to disable this functionality. This plugin provides an easy way to do so.\u003C\u002Fp>\n","Disables the XML-RPC API in WordPress 3.5+, which is enabled by default.",200000,647609,84,32,"2026-05-27T23:12:00.000Z","3.5","",[75],"xmlrpc","http:\u002F\u002Fwww.philerb.com\u002Fwp-plugins\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisable-xml-rpc.1.0.1.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":86,"downloaded":87,"rating":69,"num_ratings":88,"last_updated":89,"tested_up_to":90,"requires_at_least":91,"requires_php":73,"tags":92,"homepage":96,"download_link":97,"security_score":13,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"disable-xml-rpc-api","Disable XML-RPC-API","2.1.7","Amin Nazemi","https:\u002F\u002Fprofiles.wordpress.org\u002Faminnz\u002F","\u003Cp>Protect your website from xmlrpc brute-force attacks,DOS and DDOS attacks, this plugin disables the XML-RPC and trackbacks-pingbacks on your WordPress website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>PLUGIN FEATURES\u003C\u002Fstrong>\u003Cbr \u002F>\n(These are options you can enable or disable each one)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable access to xmlrpc.php file using .httacess file \u003C\u002Fli>\n\u003Cli>Automatically change htaccess file permission to read-only (0444)\u003C\u002Fli>\n\u003Cli>Disable X-pingback to minimize CPU usage \u003C\u002Fli>\n\u003Cli>Disable selected methods from XML-RPC\u003C\u002Fli>\n\u003Cli>Remove pingback-ping link from header\u003C\u002Fli>\n\u003Cli>Disable trackbacks and pingbacks to avoid spammers and hackers\u003C\u002Fli>\n\u003Cli>Rename XML-RPC slug to whatever you want\u003C\u002Fli>\n\u003Cli>Black list IPs for XML-RPC\u003C\u002Fli>\n\u003Cli>White list IPs for XML-RPC\u003C\u002Fli>\n\u003Cli>Some options to speed-up your wordpress website\u003C\u002Fli>\n\u003Cli>Disable JSON REST API\u003C\u002Fli>\n\u003Cli>Hide WordPress Version\u003C\u002Fli>\n\u003Cli>Disable built-in WordPress file editor\u003C\u002Fli>\n\u003Cli>Disable wlw manifest\u003C\u002Fli>\n\u003Cli>And some other options\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What is XMLRPC\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>XML-RPC, or XML Remote Procedure Call is a protocol which uses XML to encode its calls and HTTP as a transport mechanism.\u003Cbr \u002F>\nBeginning in WordPress 3.5, XML-RPC is enabled by default. Additionally, the option to disable\u002Fenable XML-RPC was removed. For various reasons, site owners may wish to disable this functionality. This plugin provides an easy way to do so.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why you should disable XML-RPC\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Xmlrpc has two main weaknesses\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force attacks:\u003Cbr \u002F>\nAttackers try to login to WordPress using xmlrpc.php with as many username\u002Fpassword combinations as they can enter. A method within xmlrpc.php allows the attacker to use a single command (system.multicall) to guess hundreds of passwords. Daniel Cid at Sucuri described it well in October 2015: “With only 3 or 4 HTTP requests, the attackers could try thousands of passwords, bypassing security tools that are designed to look and block brute force attempts.”\u003C\u002Fli>\n\u003Cli>Denial of Service Attacks via Pingback:\u003Cbr \u002F>\nBack in 2013, attackers sent Pingback requests through xmlrpc.php of approximately 2500 WordPress sites to “herd (these sites) into a voluntary botnet,” according to Gur Schatz at Incapsula. “This gives any attacker a virtually limitless set of IP addresses to Distribute a Denial of Service attack across a network of over 100 million WordPress sites, without having to compromise them.”\u003C\u002Fli>\n\u003C\u002Ful>\n","A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website",100000,815370,43,"2026-02-04T06:54:00.000Z","6.9.5","5.0",[60,93,94,95,75],"disable-xmlrpc","pingback","stop-brute-force-attacks","https:\u002F\u002Fneatma.com\u002Fdsxmlrpc-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisable-xml-rpc-api.zip",{"slug":99,"name":100,"version":101,"author":102,"author_profile":103,"description":104,"short_description":105,"active_installs":106,"downloaded":107,"rating":54,"num_ratings":108,"last_updated":109,"tested_up_to":110,"requires_at_least":111,"requires_php":112,"tags":113,"homepage":117,"download_link":118,"security_score":119,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"remove-xmlrpc-pingback-ping","Remove & Disable XML-RPC Pingback","1.6","cleverplugins","https:\u002F\u002Fprofiles.wordpress.org\u002Fcleverplugins\u002F","\u003Cp>Prevent your WordPress site from participating and being a victim of pingback denial of service attacks. \u003Cstrong>After activation the plugin automatically disables XML-RPC. There’s no need to configure anything.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>By disabling the XML-RPC pingback you’ll:\u003Cbr \u002F>\n* lower your server CPU usage\u003Cbr \u002F>\n* prevent malicious scripts from using your site to run pingback denial of service attacks\u003Cbr \u002F>\n* prevent malicious scripts to run denial of service attacks on your site via pingback\u003C\u002Fp>\n\u003Cp>From sucuri.net:\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>Any WordPress site with Pingback enabled (which is on by default) can be used in DDOS attacks against other sites.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Learn More\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fwptavern.com\u002Fhow-to-prevent-wordpress-from-participating-in-pingback-denial-of-service-attacks\" rel=\"nofollow ugc\">How To Prevent WordPress From Participating In Pingback Denial of Service Attacks\u003C\u002Fa> – wptavern.com\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fblog.sucuri.net\u002F2014\u002F03\u002Fmore-than-162000-wordpress-sites-used-for-distributed-denial-of-service-attack.html\" rel=\"nofollow ugc\">More Than 162,000 WordPress Sites Used for Distributed Denial of Service Attack\u003C\u002Fa> – sucuri.net\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fhackguard.com\u002Fxmlrpc-php-ping-backs-hackers-denial-service-attacks\" rel=\"nofollow ugc\">xmlrpc.php and Pingbacks and Denial of Service Attacks, Oh My!\u003C\u002Fa> – hackguard.com\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Is Your Site Attacking Others?\u003C\u002Fh4>\n\u003Cp>Use \u003Ca href=\"http:\u002F\u002Flabs.sucuri.net\u002F?is-my-wordpress-ddosing\" rel=\"nofollow ugc\">Sucuri’s WordPress DDOS Scanner\u003C\u002Fa> to check if your site is DDOS’ing other websites\u003C\u002Fp>\n\u003Ch4>Why Not Just Disable XMLRPC Altogether?\u003C\u002Fh4>\n\u003Cp>Yes, you can choose to do that, but if you use popular plugins like JetPack (that use XMLRPC) then those plugins will stop working. That is why this small plugin exists.\u003C\u002Fp>\n","Prevent pingback, XML-RPC and denial of service DDOS attacks by disabling the XML-RPC pingback functionality.",8000,95496,6,"2023-07-24T23:03:00.000Z","6.3.8","5.2","5.6",[114,115,94,116,75],"disable-ping","ping","xml-rpc","http:\u002F\u002Fwordpress.org\u002Fplugins\u002Fremove-xmlrpc-pingback-ping","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fremove-xmlrpc-pingback-ping.1.6.zip",85,{"slug":121,"name":122,"version":123,"author":124,"author_profile":125,"description":126,"short_description":127,"active_installs":128,"downloaded":129,"rating":13,"num_ratings":130,"last_updated":131,"tested_up_to":16,"requires_at_least":132,"requires_php":133,"tags":134,"homepage":73,"download_link":139,"security_score":13,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"stop-xml-rpc-attacks","Stop XML-RPC Attacks","2.0.0","Pascal CESCATO","https:\u002F\u002Fprofiles.wordpress.org\u002Fpcescato\u002F","\u003Cp>Stop XML-RPC Attacks protects your WordPress site from XML-RPC brute force attacks, DDoS attempts, and reconnaissance probes while maintaining compatibility with essential services like Jetpack and WooCommerce.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Three security modes: Full Disable, Guest Disable, or Selective Blocking\u003C\u002Fli>\n\u003Cli>Blocks dangerous methods: system.multicall, pingback.ping, and more\u003C\u002Fli>\n\u003Cli>Compatible with Jetpack and WooCommerce\u003C\u002Fli>\n\u003Cli>Optional user enumeration blocking\u003C\u002Fli>\n\u003Cli>Attack logging for monitoring\u003C\u002Fli>\n\u003Cli>Zero configuration required – works out of the box\u003C\u002Fli>\n\u003Cli>Clean, intuitive admin interface\u003C\u002Fli>\n\u003C\u002Ful>\n","Blocks dangerous XML-RPC methods while preserving Jetpack, WooCommerce, and mobile apps compatibility.",6000,28950,4,"2026-05-23T22:03:00.000Z","6.0","7.4",[135,136,137,138,75],"brute-force","ddos","jetpack","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstop-xml-rpc-attacks.2.0.0.zip",{"slug":141,"name":142,"version":143,"author":144,"author_profile":145,"description":146,"short_description":147,"active_installs":148,"downloaded":149,"rating":54,"num_ratings":130,"last_updated":150,"tested_up_to":151,"requires_at_least":152,"requires_php":73,"tags":153,"homepage":158,"download_link":159,"security_score":160,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"manage-xml-rpc","Manage XML-RPC","1.0.2","brainvireinfo","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrainvireinfo\u002F","\u003Cp>You can now disable XML-RPC to avoid Brute force attack for given IPs or can even enable access for some IPs. XML-RPC on WordPress is actually an API that gives developers who build mobile apps, desktop apps and other services, the ability to talk to a WordPress site. The XML-RPC API that WordPress provides gives developers, a way to write applications (for you) that can do many of the things that you can do when logged into WordPress via the web interface.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cp>Block XML-RPC by following way.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable pingback.ping, pingback.extensions.getPingbacks and Unset X-Pingback from HTTP headers, that will block bots to access specified method.\u003C\u002Fli>\n\u003Cli>Disable\u002FBlock XML-RPC for all users.\u003C\u002Fli>\n\u003C\u002Ful>\n","Enable\u002FDisable XML-RPC for all or based on IP list, also you can control pingback and Unset X-Pingback from HTTP headers.",5000,65211,"2024-12-02T07:10:00.000Z","6.7.5","4.0",[154,155,138,156,157],"block-xml-rpc","brute-force-attacks","xml-rpc-pingback","xmlrpc-php-attack","http:\u002F\u002Fwww.brainvire.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmanage-xml-rpc.1.0.2.zip",92,{"error":162,"url":163,"statusCode":164,"statusMessage":165,"message":165},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fvampire-character\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":167,"versions":168},12,[169,174,180,188,196,204,212,220,228,236,244,252],{"version":6,"download_url":26,"svn_tag_url":170,"released_at":38,"has_diff":50,"diff_files_changed":171,"diff_lines":38,"trac_diff_url":172,"vulnerabilities":173,"is_current":162},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.15\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.14&new_path=%2Fvampire-character%2Ftags%2F2.15",[],{"version":40,"download_url":175,"svn_tag_url":176,"released_at":38,"has_diff":50,"diff_files_changed":177,"diff_lines":38,"trac_diff_url":178,"vulnerabilities":179,"is_current":50},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.14.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.14\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.13&new_path=%2Fvampire-character%2Ftags%2F2.14",[],{"version":181,"download_url":182,"svn_tag_url":183,"released_at":38,"has_diff":50,"diff_files_changed":184,"diff_lines":38,"trac_diff_url":185,"vulnerabilities":186,"is_current":50},"2.13","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.13.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.13\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.12&new_path=%2Fvampire-character%2Ftags%2F2.13",[187],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":189,"download_url":190,"svn_tag_url":191,"released_at":38,"has_diff":50,"diff_files_changed":192,"diff_lines":38,"trac_diff_url":193,"vulnerabilities":194,"is_current":50},"2.12","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.12.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.12\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.10&new_path=%2Fvampire-character%2Ftags%2F2.12",[195],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":197,"download_url":198,"svn_tag_url":199,"released_at":38,"has_diff":50,"diff_files_changed":200,"diff_lines":38,"trac_diff_url":201,"vulnerabilities":202,"is_current":50},"2.10","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.10.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.10\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.9&new_path=%2Fvampire-character%2Ftags%2F2.10",[203],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":205,"download_url":206,"svn_tag_url":207,"released_at":38,"has_diff":50,"diff_files_changed":208,"diff_lines":38,"trac_diff_url":209,"vulnerabilities":210,"is_current":50},"2.9","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.9.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.9\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.8&new_path=%2Fvampire-character%2Ftags%2F2.9",[211],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":213,"download_url":214,"svn_tag_url":215,"released_at":38,"has_diff":50,"diff_files_changed":216,"diff_lines":38,"trac_diff_url":217,"vulnerabilities":218,"is_current":50},"2.8","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.8.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.8\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.7&new_path=%2Fvampire-character%2Ftags%2F2.8",[219],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":221,"download_url":222,"svn_tag_url":223,"released_at":38,"has_diff":50,"diff_files_changed":224,"diff_lines":38,"trac_diff_url":225,"vulnerabilities":226,"is_current":50},"2.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.7.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.7\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.6&new_path=%2Fvampire-character%2Ftags%2F2.7",[227],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":229,"download_url":230,"svn_tag_url":231,"released_at":38,"has_diff":50,"diff_files_changed":232,"diff_lines":38,"trac_diff_url":233,"vulnerabilities":234,"is_current":50},"2.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.5&new_path=%2Fvampire-character%2Ftags%2F2.6",[235],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":237,"download_url":238,"svn_tag_url":239,"released_at":38,"has_diff":50,"diff_files_changed":240,"diff_lines":38,"trac_diff_url":241,"vulnerabilities":242,"is_current":50},"2.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.4&new_path=%2Fvampire-character%2Ftags%2F2.5",[243],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":245,"download_url":246,"svn_tag_url":247,"released_at":38,"has_diff":50,"diff_files_changed":248,"diff_lines":38,"trac_diff_url":249,"vulnerabilities":250,"is_current":50},"2.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvampire-character%2Ftags%2F2.3&new_path=%2Fvampire-character%2Ftags%2F2.4",[251],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":253,"download_url":254,"svn_tag_url":255,"released_at":38,"has_diff":50,"diff_files_changed":256,"diff_lines":38,"trac_diff_url":38,"vulnerabilities":257,"is_current":50},"2.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvampire-character.2.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvampire-character\u002Ftags\u002F2.3\u002F",[],[258],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40}]