It appears to prevent any POST requests to wp-login.php that aren’t made from a page on my-domain.com.
When the browser sends a POST request, say after submitting a form, it will include a HTTP Referrer header telling the server where the request came from.
This theoretically prevents bots submitting POST requests directly to wp-login.php as part of a brute force attack, but the HTTP referrer is trivial to fake, so it’s not actually all that helpful.
Related Posts:
- Improve wordpress security by hiding non public resources
- File and directory permissions
- Using “wordpress_logged_in” to restrict direct access to uploads folder in 2021
- WordPress URL/Folder ReWrite using Htaccess
- Which WordPress scripts need to be executable for a fresh installation?
- Blocking access to wp-login via htaccess not working
- Attach to wp-login.php and xmlrpc.php
- XMLRPC filtering through htaccess not working
- Restricting user login by IP address
- WordPress: Adding Security
- How do I test to ensure that my wp-config file is protected?
- WordPress not seeing .htaccess rules
- Rules in .htaccess only if the requested URL is /wp-admin
- Disable directory browsing of uploads folder
- Strange behaviour of is_user_logged_in() and get_current_user_id()
- Selectively Disabling PHP via .htaccess in Root Directory
- Should I prevent access to .htaccess and wp-config.php files?
- Blocking wp-login in HTACCESS has also blocked password protected pages
- Basic Auth .htaccess on wp-login, but allow logout from woocommerce
- Using htaccess to prevent spam through wp-comments-post.php
- How can I create a private site that is inaccessible from the outside?
- Restrict Content for only Contributors via .htaccess
- Allowing access to certain WordPress created pages or posts with htaccess / htpasswd
- Why is this line of code Wrong in every WordPress .Htaccess security article?
- Default .htaccess file for WordPress?
- Security and .htaccess
- htaccess disable WordPress rewrite rules for folder and its contents
- How disable SSL redirect for specific URL?
- WordPress site displaying 404 for any page apart from index
- Which ways can be used to log in to WordPress?
- Why does the header set X-Robots-Tag apply to all pages?
- How to change “wp-admin” to something else without search-replacing the core?
- Error:406 not acceptable
- .htaccess Rewrite URL WordPress
- A plugin changes my .htaccess file and I can’t access httpd.conf as that’s a shared server
- Cant block wordpress readme files
- WordPress keeps deleting .htaccess file
- How can I code my plugin to safely modify .htaccess?
- Prevent users from browsing through the media galleries
- How to modify the .htaccess to force ssl on login and admin pages
- HTAccess stops me from accessing WordPress Dashboard links
- Server crashed trying to restore wordpress multisite, images are not found pls help
- .htaccess rewrite rule puzzle
- WordPress Redirect 301 register page
- Allow logged in users who doesn’t belong to whitelisted ips
- Best way to redirect site in subdirectory to root?
- Only expose routes with prefix /wp-json on WordPress using Apache
- Missing slash after moving site to subfolder
- WildCard SSL with wordpress subdomain
- browser caching not disabled after disabling in .htaccess
- Transfer to HTTPS – mixed content on main page only [closed]
- Htaccess redirect after changing Language URL format
- Adding a SSL Certificate
- .htaccess Security Header Rules
- mod_rewrite loop, redirecting http to https on certain section of wordpress blog
- .htaccess in subdir gets ignored by WordPress’ own .htaccess in /
- What to write in the htaccess in order to detect browser language and point accordingly?
- sitemap contains weird links and does not contain my pages [closed]
- .htaccess RewriteCond excluding directories does not work when there is an .htaccess or php.ini in subdirectory
- Separate 404 page for WordPress in subfolder
- Weird behavior of Dashboard, must be core files
- 404 error Additionally 403 Forbidden error on a URL
- Conflict with Force SSL and Rewrite Rules
- Remove trailing slash after .html extension
- Does WP suppresses .htaccess if permalinks are disabled?
- Need help rebuilding lost htaccess file
- How to rename index.php to home.php
- Creating a copy of a website in a subdirectory, wp-admin redirect problem
- disable WordPress 404 for one specific page/folder to receive actual php errors
- Troll the hackers by redirecting them
- .htpasswd asking for authentication on home page
- WordPress login fail after .htaccess domain redirect
- Redirect to new domain with .htaccess [closed]
- I am new in word pres my font awesome is not allow
- Access sub-domain when root public_html is protected with .htaccess password
- Redirect https://www.subdomain.domain.com is not redirecting to subdomain.website.com [closed]
- Can’t access htaccess [closed]
- .htaccess redirect not properly working [ ?utm_source=]
- hide theme files for admin beneath root
- Why my WordPress Site Asking for HTTP Authentication?
- Iterating users while user iteration is suppressed
- htaccess redirects invalid request to home page not 404
- Deny php execution in /wp-includes – using .htaccess in /wp-includes VS root folder
- Downloading zip or tar.gz inside WordPress installation?
- WordPress permalinks is wrong. It wants me to change my htaccess file. But then site crashes
- How to move wordpress website from hosting account to localhost
- Clicking PUBLISH Now Redirects to 404 PAGE NOT FOUND
- Unable to find ‘full-path’ to my 404.php file
- Use htaccess to redirect wordpress non-existent page to homepage
- WordPress RSS feed to external XML
- Does htaccess password keep search engines out?
- Need to edit htaccess while moving on WordPress
- block seacrh engines for all pages EXCEPT homepage
- Issue after changing permalink structure [duplicate]
- My WP site and password was hacked, what to do? [closed]
- rewrite rule on plugin activation
- Url redirection using htacess for my website
- htaccess – Server Subdirectory With Different Name Than URL Subdirectory
- The connection to “domain” is not secure
- cant access website thru www only works on direct xyz.com