Restrict xmlrpc to JETPACK
Below fixes xmlrpc.php attacks, allowing server-wide access only to Wordpress's JETPACK.
1. Navigate to "Apache Configuration" in WHM
2. Select "Include Editor"
3. Select "Pre Virtualhost Include" and hit "All Versions"
Paste the below code into the bottom of the script editor that opens:
<FilesMatch "^(xmlrpc\.php)">
Order Deny,Allow
# Whitelist Jetpack/ Automattic CIDR IP Address Blocks
Allow from 192.0.64.0/18
Allow from 209.15.0.0/16
Allow from 66.155.0.0/17
Deny from all
</FilesMatch>
4. Restart Apache