Scans Target Wordfence-Protected WordPress Sites
Executive Summary
Sensors detected a small number of scans targeting the Wordfence WAF script (wordfence-waf.php) on WordPress sites. The scans began yesterday and indicate attempts to probe the WAF for potential vulnerabilities. Wordfence installs this script in the site root during setup.
Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-09-29T13:29:33+00:00 - Category: threat-intel
Original Description: Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will be created in the site&#;x26;#;39;s root directory [1].
"A rolling stone gathers no moss."
— Publilius Syrus