Security advisorywp2shell: WordPress core vulnerability. Updated August 4, 2026.

Read the advisory

Troubleshooting

Jetpack compatibility (XML-RPC)

How Security Ninja XML-RPC hardening interacts with Jetpack and how to keep Jetpack working.

Security Ninja can flag or help harden xmlrpc.php. Many sites do not need XML-RPC. Jetpack (and some other remote tools) still do.

If you applied an XML-RPC block via a functions.php snippet, .htaccess rule, or a Security Ninja fix that disables XML-RPC, Jetpack features that rely on it can fail.

Two fixes related to xmlrpc.php

What to do

  1. If you use Jetpack, do not leave XML-RPC fully blocked.
  2. Remove any custom .htaccess / theme code that denies xmlrpc.php, or turn off the related fix in Security Ninja → Fixes if you enabled one.
  3. Re-test Jetpack connection and the features you need.

You can still use other hardening (strong passwords, 2FA, firewall login protection) without blocking XML-RPC.

Still stuck? Get help or contact us.