Alarming Vulnerabilities Found in Singapore’s WordPress Sites: Study Reveals Security Shortcomings
A recent study conducted by Equinet Academy and Cutlazz Cyber Consulting has unveiled troubling findings regarding the security posture of WordPress websites managed by businesses in Singapore. Published on August 31, 2026, the report reveals that nearly 80% of the 102 examined WordPress sites harbor at least one identifiable security vulnerability, with significant implications for both the organizations involved and their clientele.
The research, which spanned from April to August 2026, highlighted that 33.3% of the sites fell into the High or Critical Risk categories. Specifically, seven of the websites were deemed to carry Critical Risk ratings because they exhibited vulnerabilities that could be exploited by malicious actors. In total, researchers identified 1,853 confirmed vulnerabilities that correlated with Common Vulnerabilities and Exposures (CVE) entries.
To conduct this analysis, the study utilized the WPSec Automated Scanner. This passive automated tool assessed publicly accessible data, including the versions of WordPress in use, lists of plugins, matching vulnerabilities to CVE entries, header configurations, and exposed system endpoints. Notably, researchers refrained from attempts at authenticated access or brute-force attacks, focusing strictly on examining Singapore-registered domains or those hosted on Singaporean IP addresses. The target demographic for this study mainly comprised small and medium-sized businesses, explicitly excluding multinational subsidiaries.
The findings highlighted outdated software as the primary culprit for these security lapses. Alarmingly, 40% of the assessed sites were using outdated versions of the WordPress core software, with some installations dating back to 2015. Every site flagged as being at Critical Risk was found to be operating on similarly outdated core software. Furthermore, plugin vulnerabilities exacerbated the situation, as 70.6% of the sites utilized at least one plugin with a known CVE, while 65.7% operated with outdated plugins.
In addition to software vulnerabilities, the study documented various configuration weaknesses. For instance, 56.9% of the assessed sites had their XML-RPC functionality publicly exposed, and 54.9% allowed wp-cron to be publicly accessible. Concerns were also raised regarding potential information leakage, as 29.4% of the examined sites revealed sensitive login paths through their robots.txt files, further increasing their risk profiles.
The average risk score calculated across all assessed sites reached a concerning figure of 42.1 out of 100, categorizing these websites at the upper end of Elevated Risk. Dylan Sun, the Founder and Managing Director of Equinet Academy, pointed out that many of the vulnerabilities arose from neglected maintenance practices and the failure to update default configurations, rather than from sophisticated attacks. This suggests a pressing need for businesses to implement basic routine security practices rather than relying solely on complex defensive strategies.
The risks associated with these vulnerabilities extend beyond mere proactive defense measures, particularly for organizations that collect personal data. The unresolved vulnerabilities may pose compliance risks under Singapore’s Personal Data Protection Act (PDPA), which necessitates reasonable security safeguards to protect personal information. The report makes several recommendations to mitigate these risks, including the implementation of HTTPS across all pages, updating WordPress core and plugin versions regularly, disabling unused XML-RPC functions, reviewing the visibility of login paths, and restricting access to sensitive files such as readme.html and wp-cron.php.
Additionally, the researchers advocate for conducting comprehensive security scans on at least a quarterly basis. While owning a vulnerability does not automatically indicate a breach has occurred, it is worth noting that the same information could be reconnaissance territory for potential cybercriminals performing standard scans.
In conclusion, the findings of this study serve as a wake-up call for Singaporean businesses relying on WordPress for their digital presence. By taking proactive steps to address these identified vulnerabilities, organizations can significantly enhance their security measures and safeguard against potentially devastating cyber threats. The study underscores a critical shift towards prioritizing routine security maintenance and best practices as foundational elements of effective WordPress site protection.
For further insights and in-depth information, the original study can be found at The Cyber Express.

