What is "http://mysite.com/wp-config.php" mean?

Yes, it is most likely a bot probing than it is anyone specifically targeting your site.
If you look at your logs you will probably find other requests made for non-existent files.

For example, some plugins even require permissions to be set to 777 in order to “work”

There are sites that publish known vulnerabilities.
Good in that others can take steps to fix or remove the vulnerability.
Bad in that script-kiddies will look for sites with the vulnerability.

2 Likes