Wordpress Shit
The Hostinger website givwa a more detailed explanation:
xmlrpc.php is a WordPress core file that allows external applications to communicate with your website remotely. It uses the XML-RPC (XML Remote Procedure Call) protocol, which sends XML-formatted requests over HTTP to perform actions such as publishing posts, managing content through mobile apps, and handling pingbacks.
While xmlrpc.php was useful for early WordPress integrations, it is now unnecessary for most modern websites. Most current tools rely on the WordPress REST API instead, which uses JSON and supports more modern authentication workflows. Attackers target XML-RPC for brute-force logins, system.multicall abuse, and pingback floods that overwhelm servers in a DDoS (Distributed Denial of Service) attack, because it relies on older access methods.
For most WordPress site owners, the safest approach is to disable or restrict xmlrpc.php unless a specific plugin, mobile app, or external service still needs it. This can be done with a security plugin, server rules such as .htaccess on Apache, or a web application firewall.
RPC
In distributed computing, a remote procedure call (RPC) is an action in which a computer program causes a procedure (subroutine) to execute in a different address space of the current process (commonly on another computer on a shared computer network), which is written as if it were a normal (local) procedure call, without the programmer explicitly writing the details for the remote interaction. That is, the programmer writes essentially the same code whether the subroutine is local to the executing program, or remote. This is a form of server interaction (caller is client, executor is server), typically implemented via a request–response message passing system. In the object-oriented programming paradigm, RPCs are represented by remote method invocation (RMI). The RPC model implies a level of location transparency, namely that calling procedures are largely the same whether they are local or remote, but usually, they are not identical, so local calls can be distinguished from remote calls. Remote calls are usually orders of magnitude slow er and less reliable than local calls, so distinguishing them is important.
xmlrpc.php
xmlrpc.php is a Wordpress Remote Procedure Call "module" that can be used positively and by hackers to compromise a Wordpress webite.
Wordpress say in their website: (or it could be hostinger)
XML-RPC on WordPress is actually an API that allows developers who make 3rd party application and services the ability to interact to your WordPress site. The XML-RPC API that WordPress provides several key functionalities that include:
What hostinger.co.uk say about xmlrpc.php
Why You Should Disable Xmlrpc.php
The biggest issues with XML-RPC are the security concerns that arise. The issues aren’t with XML-RPC directly, but instead how the file can be used to enable a brute force attack on your site.
Sure, you can protect yourself with incredibly strong passwords, and WordPress security plugins. But, the best mode of protection is to simply disable it.
There are two main weaknesses to XML-RPC which have been exploited in the past.
The first is using brute force attacks to gain entry to your site. An attacker will try to access your site using xmlrpc.php
by using various username and password combinations. They can effectively use a single command to test hundreds of different passwords. This allows them to bypass security tools that typically detect and block brute force attacks.
The second was taking sites offline through a DDoS attack. Hackers would use the pingback feature in WordPress to send pingbacks to thousands of sites instantaneously. This feature in xmlrpc.php gives hackers a nearly endless supply of IP addresses to distribute a DDoS attack over.