# Scanners probe for Wordfence-protected WordPress sites

Published: 2026-09-29 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/3a31cf44-6120-5b4b-9a02-f8c354573794/scanners-probe-for-wordfence-protected-wordpress-sites

> SANS ISC observed low-volume scans for wordfence-waf.php, likely used to fingerprint or bypass Wordfence-protected WordPress sites via direct IP access.

SANS Internet Storm Center reported a small number of scans targeting the file "wordfence-waf.php", a component created during installation of the Wordfence WordPress security plugin. The scans are notably bare, using only a minimal HTTP request with a Host header set to the target's IP address rather than its hostname, and lacking a User-Agent or other typical headers. The file itself contains no secrets or configuration data but does include scripts that run before WordPress code loads, integrating with Wordfence's Web Application Firewall (WAF).

The analyst offers two possible motivations for attackers: first, to enumerate which sites are protected by Wordfence, allowing attackers to avoid those sites and preserve the shelf life of exploits (since Wordfence publishes threat intelligence from protected sites that can "burn" techniques used against them); second, to identify sites reachable directly via IP address, potentially bypassing Wordfence's protection if the site's origin server accepts direct IP connections and doesn't enforce hostname-based routing through the WAF.

Defenders running Wordfence should ensure they have implemented Wordfence's "Extended Protection" feature, which is specifically designed to prevent this type of direct-IP bypass, and should follow Wordfence's guidance on preventing WAF bypass via direct origin access. This is a reconnaissance/scanning report rather than a confirmed exploitation campaign, and no indicators of compromise beyond the scan pattern (unusual bare requests for wordfence-waf.php with IP-based Host headers) were provided.

Source reporting: https://isc.sans.edu/diary/rss/33382

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3a31cf44-6120-5b4b-9a02-f8c354573794/scanners-probe-for-wordfence-protected-wordpress-sites.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
