• Hi,

    We have been seeing CPU spikes a lot, and when we opened the error log on server, we found these 401 queries are hitting us every second after the latest WordPress update.

    Cannot understand how to stop or block them.

    2026-09-20 13:30:42Error71.200.108.148401GET /wp-json/wp/v2/tags/86505 HTTP/1.1Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.362.66 KApache SSL/TLS access

    2026-09-20 13:30:43Error113.212.108.25401GET /wp-json/wp/v2/posts/17402 HTTP/1.1Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.362.66 KApache SSL/TLS access

    2026-09-20 13:30:43Error217.43.172.30401GET /wp-json/wp/v2/posts/27855 HTTP/1.1Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.362.66 KApache SSL/TLS access

    2026-09-20 13:30:45Error103.166.248.18401GET /wp-json/wp/v2/posts/116433 HTTP/1.1Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.362.66 KApache SSL/TLS access

    2026-09-20 13:30:45Error189.219.190.120401GET /wp-json/wp/v2/tags/95886 HTTP/1.1Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.362.66 KApache SSL/TLS access

    2026-09-20 13:30:47Error38.226.139.85401GET /wp-json/wp/v2/tags/89858 HTTP/1.1Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.362.66 KApache SSL/TLS access

    https://prnt.sc/DazZsz2pmiwa

    Please do Help.

    Best Regards

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
  • Rezwan Shiblu

    (@rezwanshiblu1952)

    Those 401s mean the requests are already being refused, so nothing is getting through. The CPU hit is just the volume, since each one still loads WordPress before it gets rejected. The IPs are all different too, so blocking them one by one won’t help much. Rate limiting or blocking /wp-json/ at the server or CDN level, before PHP runs, is what actually brings the load down.

    One thing worth checking, a logged out request to /wp-json/wp/v2/posts/123 on a published post normally returns 200, not 401. Do you have a security plugin or a host firewall rule that restricts the REST API for logged out visitors? That would explain the 401 and tell you where to add the rate limiting.

    @m3gadeath I see you’re using cloudflare. The wp-json are dynamic requests, by default its not handled by cloudflare. The only problem i see, your server can get flooded with such requests. It’s a problem for all wordpress sites.

    The best would be, you block the requests already with cloudflare, for not authenticated users. Not sure, if this is possible.

    Thread Starter m3gadeath

    (@m3gadeath)

    Thanks everyone, we found out that the error was caused by a plugin called Disable XML-RPC-API. When disable json was turned on in it.

    Sadly at the same time, someone was also trying to sophisticate DDOS us. Really bad people in the world. Hence ultra CPU spike at the same time.

    • This reply was modified 1 week ago by m3gadeath.
    Rezwan Shiblu

    (@rezwanshiblu1952)

    Glad you found it. That explains the 401s. If the plugin was blocking the REST API for logged out visitors, every one of those requests would get refused.

    The thing is, they still had to load WordPress first before getting blocked, so the CPU cost stayed the same. With the attack traffic on top, blocking or rate limiting /wp-json/ at your CDN or server level would help more, since it stops them before PHP runs.

    You can mark the topic resolved once things settle.

    Glad you found what was causing the 401 errors. Has the CPU usage settled after changing that setting or is it still spiking?

    One thing I would be careful with is blocking everything under /wp-json/ because the WordPress editor and some plugins need it. WordPress also warns against disabling the REST API

    If the CPU spikes are still there ask your host to compare the request logs with the exact spike times. That should help confirm which requests are actualy causing the load. Then target that traffic insted of blocking normal requests too

    The 401 messages stopping would confirm that part is fixed but not necessarily the CPU issue

Viewing 5 replies - 1 through 5 (of 5 total)

You must be logged in to reply to this topic.