Scanners probe for Wordfence-protected WordPress sites
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
SANS ISC observed low-volume scans for wordfence-waf.php, likely used to fingerprint or bypass Wordfence-protected WordPress sites via direct IP access.
SANS Internet Storm Center reported a small number of scans targeting the file "wordfence-waf.php", a component created during installation of the Wordfence WordPress security plugin. The scans are notably bare, using only a minimal HTTP request with a Host header set to the target's IP address rather than its hostname, and lacking a User-Agent or other typical headers. The file itself contains no secrets or configuration data but does include scripts that run before WordPress code loads, integrating with Wordfence's Web Application Firewall (WAF).
The analyst offers two possible motivations for attackers: first, to enumerate which sites are protected by Wordfence, allowing attackers to avoid those sites and preserve the shelf life of exploits (since Wordfence publishes threat intelligence from protected sites that can "burn" techniques used against them); second, to identify sites reachable directly via IP address, potentially bypassing Wordfence's protection if the site's origin server accepts direct IP connections and doesn't enforce hostname-based routing through the WAF.
Defenders running Wordfence should ensure they have implemented Wordfence's "Extended Protection" feature, which is specifically designed to prevent this type of direct-IP bypass, and should follow Wordfence's guidance on preventing WAF bypass via direct origin access. This is a reconnaissance/scanning report rather than a confirmed exploitation campaign, and no indicators of compromise beyond the scan pattern (unusual bare requests for wordfence-waf.php with IP-based Host headers) were provided.
Source reporting: https://isc.sans.edu/diary/rss/33382
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,316 reports from 152 sources, 2,734 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs