CYBER DELTA FORCESearch

4 in 5 Singapore Business Websites Have WordPress Vulnerabilities

A new Singapore Study has found that four in five websites run by local businesses carry at least one detectable WordPress vulnerabilities.

CDF News DeskThe Cyber Express15 Sept 2026, 1:53 pm
Image courtesy of The Cyber Express. Original report
CDF REPORT

A new Singapore Study has found that four in five websites run by local businesses carry at least one detectable WordPress vulnerabilities. The Singapore WordPress Website Cybersecurity Study, released by Equinet Academy on August 31, 2026, in partnership with Cutlazz Cyber Consulting, examined 102 publicly accessible WordPress sites operated by Singapore-based businesses. Across the sample, 1,853 confirmed vulnerabilities were matched to documented CVEs, and the average risk score came in at 42.1 out of 100 — placing the group at the upper end of "Elevated Risk." Outdated Software Drives WordPress Vulnerabilities Aging software was a recurring theme. Of the 102 sites, 41 (40.2%) were running outdated WordPress core versions, some dating back to 2015.

Methodology and Limitations Researchers used the WPSec Automated Scanner to assess publicly visible data — WordPress versions, plugin inventories, CVE matches, header configurations, and exposed endpoints — without attempting authenticated access, brute-force entry, or exploitation of any flaws found. Compliance and Business Implications For sites that collect personal data, unresolved vulnerabilities in CMS software may also carry compliance risk under Singapore's Personal Data Protection Act (PDPA), which requires reasonable security safeguards. The report recommends businesses adopt HTTPS across their sites, keep WordPress core and plugins current, disable unused XML-RPC functionality, review login-path visibility, restrict access to files like readme.html and wp-cron.php, and run security scans at least quarterly.

What changed

He noted that unpatched software and unreviewed configurations accumulate risk over time, and that regularly updating systems and checking public-facing exposure are practical ways businesses can cut down avoidable risk.

Why this matters

Methodology and Limitations Researchers used the WPSec Automated Scanner to assess publicly visible data — WordPress versions, plugin inventories, CVE matches, header configurations, and exposed endpoints — without attempting authenticated access, brute-force entry, or exploitation of any flaws found.

Compliance and Business Implications For sites that collect personal data, unresolved vulnerabilities in CMS software may also carry compliance risk under Singapore's Personal Data Protection Act (PDPA), which requires reasonable security safeguards.

The report recommends businesses adopt HTTPS across their sites, keep WordPress core and plugins current, disable unused XML-RPC functionality, review login-path visibility, restrict access to files like readme.html and wp-cron.php, and run security scans at least quarterly.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.

MORE IN VULNERABILITIES

More cybersecurity reporting

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesSecurityWeek · 15 Sept 2026, 4:36 pmCisco Secure Email Gateway zero-day exploited to gain root command executionThe Hacker News · 15 Sept 2026, 11:41 am'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · 15 Sept 2026, 3:07 amHomebrew 7.0.0 gets built-in GUI, better security controlsBleepingComputer · 15 Sept 2026, 1:21 am