I cannot believe that Wordpress still ships without basic rate limiting on its login form.
Parsing a url and returning 404 from nginx is cheap and scalable, and allows through legitimate traffic that may be sharing an IP (such as TOR).