4 in 5 Singapore Business Websites Have WordPress Vulnerabilities
A new Singapore Study has fo 2026-9-15 08:26:10 Author: thecyberexpress.com(查看原文) 阅读量:8 收藏

WordPress Vulnerabilities

A new Singapore Study has found that four in five websites run by local businesses carry at least one detectable WordPress vulnerabilities. The Singapore WordPress Website Cybersecurity Study, released by Equinet Academy on August 31, 2026, in partnership with Cutlazz Cyber Consulting, examined 102 publicly accessible WordPress sites operated by Singapore-based businesses.  

Using passive, automated scanning between April and August 2026, researchers found that 80.4% of the sites had at least one identifiable vulnerability, and 33.3% fell into the High or Critical Risk categories. Seven sites were rated Critical Risk. 

Across the sample, 1,853 confirmed vulnerabilities were matched to documented CVEs, and the average risk score came in at 42.1 out of 100 — placing the group at the upper end of “Elevated Risk.” 

Outdated Software Drives WordPress Vulnerabilities 

Aging software was a recurring theme. Of the 102 sites, 41 (40.2%) were running outdated WordPress core versions, some dating back to 2015. Notably, every site flagged Critical Risk was also running outdated core software. 

Plugins added further exposure: 70.6% of sites had at least one plugin with a confirmed CVE, and 65.7% had at least one outdated plugin, with 199 outdated plugin installations counted overall. 

Other findings included: 

  • 56.9% had XML-RPC publicly exposed 
  • 54.9% had wp-cron publicly accessible 
  • 29.4% revealed their login path through robots.txt 

Most Gaps Stem From Routine Maintenance, Not Sophisticated Attacks 

The study concluded that many of these vulnerabilities in CMS setups weren’t the product of advanced hacking techniques but of neglected upkeep and default configurations left unchanged. 

Dylan Sun, Founder and Managing Director of Equinet Academy, said the results show that WordPress security often comes down to basics rather than elaborate defenses. He noted that unpatched software and unreviewed configurations accumulate risk over time, and that regularly updating systems and checking public-facing exposure are practical ways businesses can cut down avoidable risk. 

Methodology and Limitations 

Researchers used the WPSec Automated Scanner to assess publicly visible data — WordPress versions, plugin inventories, CVE matches, header configurations, and exposed endpoints — without attempting authenticated access, brute-force entry, or exploitation of any flaws found.  

The results reflect a snapshot of visible indicators rather than a full audit, and a detected vulnerability doesn’t necessarily mean a site has been breached. Still, the study points out that the same information is just as discoverable to potential attackers running routine scans. 

Compliance and Business Implications 

For sites that collect personal data, unresolved vulnerabilities in CMS software may also carry compliance risk under Singapore’s Personal Data Protection Act (PDPA), which requires reasonable security safeguards. 

The report recommends businesses adopt HTTPS across their sites, keep WordPress core and plugins current, disable unused XML-RPC functionality, review login-path visibility, restrict access to files like readme.html and wp-cron.php, and run security scans at least quarterly. 

The Singapore Study analyzed sites selected by Singapore-registered domains or Singapore-hosted IPs, focusing on small and medium-sized businesses while excluding multinational subsidiaries. 


文章来源: https://thecyberexpress.com/wordpress-vulnerabilities-singapore-study/
如有侵权请联系:admin#unsafe.sh