WordPress wlwmanifest.xml Scanner for 2026-10-02
Oct 02, 2026
Exploitation
Last Updated: 00:00 UTC
Bulk scanning for /wp-includes/wlwmanifest.xml, the Windows Live Writer manifest present on default WordPress installs. Hitting many hosts in sequence is the fingerprinting stage of a WordPress-targeted campaign that enumerates installs before launching plugin/theme exploits.
MITRE ATT&CK
Tactic: Reconnaissance (TA0043)
Technique: T1595.002 — Active Scanning: Vulnerability Scanning
Observed URIs
Attackers by Country
| France | 1 | 100.0% |
IP Address : ASN : City/Provider
- 143.244.57.84 : AS60068 datacamp limited : Paris