Today i found that my web server doesn’t make Directory Listing by default. And this can be a vulnerable for WordPress since wp-content directory can be exploit. So test your blog, if your web server doesn’t turn off the directory listing by default please follow this steps (only works for Apache web server):
- Create or Edit existing .htaccess
- Add this code there:
- Save and close .htaccess file
- Test It!
That step will turn off the Directory Listing. Thank you for reading, and have a nice day… 🙂