91
Hacked WordPress sites use visitors' browsers to hack other sites
(www.bleepingcomputer.com)
will cause the visitor's browser to quietly upload a file using the WordPress site's XMLRPC interface
It's absurd that XMLRPC is still not disabled by default.
It's been an unnecessary weak point in the attack surface for many years.
This is a most excellent place for technology news and articles.