HomeCyber Balkans80% of WordPress Sites Are Vulnerable

80% of WordPress Sites Are Vulnerable

Published on

spot_img

Alarming Vulnerabilities Found in Singapore’s WordPress Sites: Study Reveals Security Shortcomings

A recent study conducted by Equinet Academy and Cutlazz Cyber Consulting has unveiled troubling findings regarding the security posture of WordPress websites managed by businesses in Singapore. Published on August 31, 2026, the report reveals that nearly 80% of the 102 examined WordPress sites harbor at least one identifiable security vulnerability, with significant implications for both the organizations involved and their clientele.

The research, which spanned from April to August 2026, highlighted that 33.3% of the sites fell into the High or Critical Risk categories. Specifically, seven of the websites were deemed to carry Critical Risk ratings because they exhibited vulnerabilities that could be exploited by malicious actors. In total, researchers identified 1,853 confirmed vulnerabilities that correlated with Common Vulnerabilities and Exposures (CVE) entries.

To conduct this analysis, the study utilized the WPSec Automated Scanner. This passive automated tool assessed publicly accessible data, including the versions of WordPress in use, lists of plugins, matching vulnerabilities to CVE entries, header configurations, and exposed system endpoints. Notably, researchers refrained from attempts at authenticated access or brute-force attacks, focusing strictly on examining Singapore-registered domains or those hosted on Singaporean IP addresses. The target demographic for this study mainly comprised small and medium-sized businesses, explicitly excluding multinational subsidiaries.

The findings highlighted outdated software as the primary culprit for these security lapses. Alarmingly, 40% of the assessed sites were using outdated versions of the WordPress core software, with some installations dating back to 2015. Every site flagged as being at Critical Risk was found to be operating on similarly outdated core software. Furthermore, plugin vulnerabilities exacerbated the situation, as 70.6% of the sites utilized at least one plugin with a known CVE, while 65.7% operated with outdated plugins.

In addition to software vulnerabilities, the study documented various configuration weaknesses. For instance, 56.9% of the assessed sites had their XML-RPC functionality publicly exposed, and 54.9% allowed wp-cron to be publicly accessible. Concerns were also raised regarding potential information leakage, as 29.4% of the examined sites revealed sensitive login paths through their robots.txt files, further increasing their risk profiles.

The average risk score calculated across all assessed sites reached a concerning figure of 42.1 out of 100, categorizing these websites at the upper end of Elevated Risk. Dylan Sun, the Founder and Managing Director of Equinet Academy, pointed out that many of the vulnerabilities arose from neglected maintenance practices and the failure to update default configurations, rather than from sophisticated attacks. This suggests a pressing need for businesses to implement basic routine security practices rather than relying solely on complex defensive strategies.

The risks associated with these vulnerabilities extend beyond mere proactive defense measures, particularly for organizations that collect personal data. The unresolved vulnerabilities may pose compliance risks under Singapore’s Personal Data Protection Act (PDPA), which necessitates reasonable security safeguards to protect personal information. The report makes several recommendations to mitigate these risks, including the implementation of HTTPS across all pages, updating WordPress core and plugin versions regularly, disabling unused XML-RPC functions, reviewing the visibility of login paths, and restricting access to sensitive files such as readme.html and wp-cron.php.

Additionally, the researchers advocate for conducting comprehensive security scans on at least a quarterly basis. While owning a vulnerability does not automatically indicate a breach has occurred, it is worth noting that the same information could be reconnaissance territory for potential cybercriminals performing standard scans.

In conclusion, the findings of this study serve as a wake-up call for Singaporean businesses relying on WordPress for their digital presence. By taking proactive steps to address these identified vulnerabilities, organizations can significantly enhance their security measures and safeguard against potentially devastating cyber threats. The study underscores a critical shift towards prioritizing routine security maintenance and best practices as foundational elements of effective WordPress site protection.

For further insights and in-depth information, the original study can be found at The Cyber Express.

Source link

Latest articles

Exposed Vite Servers Being Probed for AWS and Azure Credentials

F5 Reports Surge in Attacks Targeting Vite and Associated Vulnerabilities F5 Networks has recently provided...

AI Scaling and the Challenges of Access Control Webinar

ISMG Welcomes New Registrants with a Comprehensive Profile Setup In an effort to enhance user...

Microsoft Issues Emergency Patch to Address RDS Vulnerability

Microsoft Resolves Critical Remote Desktop and Hyper-V Issues, Enhancing IT Operations This week, IT teams...

Weekly Cybersecurity Newsletter – Top 50 Cyber Stories of the Week (Sep 7–12)

Microsoft Addresses 973 CVEs, Automated Attacks by Claude Agents, and More: A Weekly Cybersecurity...

More like this

Exposed Vite Servers Being Probed for AWS and Azure Credentials

F5 Reports Surge in Attacks Targeting Vite and Associated Vulnerabilities F5 Networks has recently provided...

AI Scaling and the Challenges of Access Control Webinar

ISMG Welcomes New Registrants with a Comprehensive Profile Setup In an effort to enhance user...

Microsoft Issues Emergency Patch to Address RDS Vulnerability

Microsoft Resolves Critical Remote Desktop and Hyper-V Issues, Enhancing IT Operations This week, IT teams...