![]() |
Equinet Academy analysis of 102 Singapore business websites finds one in three rated High or Critical Risk and 40.2% running outdated WordPress core versions
SINGAPORE, Sept. 15, 2026 /PRNewswire/ -- Four in five WordPress websites operated by Singapore-based businesses had at least one detectable cybersecurity vulnerability, according to the Singapore WordPress Website Cybersecurity Study, published by Equinet Academy on 31 August 2026 in partnership with Cutlazz Cyber Consulting.
The study analysed 102 publicly accessible WordPress websites operated by Singapore-based businesses between April and August 2026 using passive, automated security scanning. Researchers found that 80.4% of sites had at least one detectable vulnerability, while 33.3% were rated High or Critical Risk under the study's risk-scoring methodology. Seven websites fell into the Critical Risk category.
Across the websites analysed, researchers identified 1,853 confirmed vulnerabilities matched against documented Common Vulnerabilities and Exposures (CVEs). The average risk score across the sample was 42.1 out of 100, placing the overall cohort at the upper end of the study's Elevated Risk category.
Outdated WordPress Software Emerges as a Major Risk Factor
One of the study's clearest findings was the prevalence of ageing WordPress installations.
40.2% of the websites, or 41 out of 102, were running an outdated WordPress core version. Some detected installations were running versions dating back to 2015. All seven websites classified as Critical Risk were also running an outdated version of WordPress.
Plugin maintenance represented another major area of exposure. 70.6% of websites had at least one CVE-confirmed plugin vulnerability, while 65.7% had at least one outdated plugin installed. The study detected 199 outdated plugin installations across the sample.
Key findings
80.4%, or 82 of 102 websites, had at least one detectable vulnerability. 1,853 confirmed vulnerabilities were matched against documented CVEs. 33.3%, or 34 websites, were rated High or Critical Risk. 7 websites were classified as Critical Risk. 40.2%, or 41 websites, were running an outdated WordPress core. 70.6%, or 72 websites, had at least one confirmed plugin vulnerability. 65.7%, or 67 websites, had at least one outdated plugin installed. 56.9%, or 58 websites, had XML-RPC publicly exposed. 54.9%, or 56 websites, had wp-cron publicly exposed. 29.4%, or 30 websites, exposed their WordPress login path through robots.txt.Many of the Risks Are Preventable
The study found that many of the detected exposures were associated not with sophisticated attack techniques, but with routine maintenance gaps and default WordPress configurations.
Common issues included outdated WordPress installations, ageing plugins, exposed XML-RPC functionality, publicly accessible wp-cron endpoints and visible WordPress login paths.
The report notes that these exposures can often be reduced through basic measures such as keeping WordPress core and plugins updated, reviewing default configurations, restricting unnecessary public endpoints and conducting regular security scans.
"The findings show that WordPress security is not only about defending against sophisticated cyberattacks. A significant amount of exposure can come from basic maintenance issues that accumulate over time. Keeping software updated, reviewing configurations and regularly checking what is publicly exposed are practical steps businesses can take to reduce unnecessary risk."
Dylan Sun, Founder and Managing Director, Equinet Academy
Publicly Visible Security Gaps Can Be Detected Through Automated Scanning
The research was conducted using the WPSec Automated Scanner, which analysed publicly visible information including WordPress versions, plugin inventories, known CVE exposure, header configurations and exposed WordPress endpoints.
No authenticated access was obtained. No brute-force attacks or attempts to exploit detected vulnerabilities were conducted.
The findings therefore represent a point-in-time assessment of publicly visible cybersecurity indicators, rather than a complete security audit. The presence of a vulnerability also does not confirm that a website has been actively exploited.
The study nevertheless highlights that many of these indicators are discoverable through routine automated reconnaissance, meaning similar information may also be visible to threat actors scanning publicly accessible websites.
Implications for Singapore Businesses
Where websites collect or process personal data, inadequate security controls may also create compliance exposure under Singapore's Personal Data Protection Act (PDPA), which requires organisations to make reasonable security arrangements to protect personal data.
The report recommends that businesses prioritise HTTPS across their websites, keep WordPress core and plugins updated, disable unnecessary XML-RPC functionality, review WordPress login-path exposure, restrict unnecessary access to files and endpoints such as readme.html and wp-cron.php, and conduct security scans at least quarterly.
About the Singapore WordPress Website Cybersecurity Study
The Singapore WordPress Website Cybersecurity Study examines publicly visible cybersecurity risks affecting WordPress websites operated by Singapore-based businesses.
The study analysed 102 websites between April and August 2026. Sites were selected based on Singapore-registered domains or Singapore-hosted IP addresses, with a focus on small and medium-sized businesses. Multinational subsidiaries were excluded.
The research used passive, non-intrusive automated scanning and was published on 31 August 2026 by Equinet Academy in partnership with Cutlazz Cyber Consulting.
About Equinet Academy
Equinet Academy is a SkillsFuture Singapore Registered Training Provider that trains working professionals across digital marketing, data analytics, SEO, paid media, social media and artificial intelligence.
The Singapore WordPress Website Cybersecurity Study forms part of Equinet Academy's commitment to producing Singapore-specific, data-backed research that supports the local business community and helps organisations make informed decisions about their digital infrastructure.
About Cutlazz
Cutlazz Pte Ltd is a global cybersecurity firm providing threat-informed defence solutions. Its services include Proactive Cyber Consulting, Virtual CISO services, Purple Teaming-as-a-Service and PCI DSS Advisory across sectors including finance, healthcare, government and technology.
The study was co-validated by Torry J. Henderson, CEO of Cutlazz Pte Ltd.
2 hours ago
9 
English (United States)