xmlrpc.php should be disabled in Wordpress except if specific use case. In .htaccess file:
<Files xmlrpc.php> order deny,allow deny from all allow from xxx.xxx.xxx.xxx </Files>