4 in 5 Singapore Business Websites Have WordPress Vulnerabilities
A new Singapore Study has found that four in five websites run by local businesses carry at least one detectable WordPress vulnerabilities.

A new Singapore Study has found that four in five websites run by local businesses carry at least one detectable WordPress vulnerabilities. The Singapore WordPress Website Cybersecurity Study, released by Equinet Academy on August 31, 2026, in partnership with Cutlazz Cyber Consulting, examined 102 publicly accessible WordPress sites operated by Singapore-based businesses. Across the sample, 1,853 confirmed vulnerabilities were matched to documented CVEs, and the average risk score came in at 42.1 out of 100 — placing the group at the upper end of "Elevated Risk." Outdated Software Drives WordPress Vulnerabilities Aging software was a recurring theme. Of the 102 sites, 41 (40.2%) were running outdated WordPress core versions, some dating back to 2015.
Methodology and Limitations Researchers used the WPSec Automated Scanner to assess publicly visible data — WordPress versions, plugin inventories, CVE matches, header configurations, and exposed endpoints — without attempting authenticated access, brute-force entry, or exploitation of any flaws found. Compliance and Business Implications For sites that collect personal data, unresolved vulnerabilities in CMS software may also carry compliance risk under Singapore's Personal Data Protection Act (PDPA), which requires reasonable security safeguards. The report recommends businesses adopt HTTPS across their sites, keep WordPress core and plugins current, disable unused XML-RPC functionality, review login-path visibility, restrict access to files like readme.html and wp-cron.php, and run security scans at least quarterly.
What changed
He noted that unpatched software and unreviewed configurations accumulate risk over time, and that regularly updating systems and checking public-facing exposure are practical ways businesses can cut down avoidable risk.
Why this matters
Methodology and Limitations Researchers used the WPSec Automated Scanner to assess publicly visible data — WordPress versions, plugin inventories, CVE matches, header configurations, and exposed endpoints — without attempting authenticated access, brute-force entry, or exploitation of any flaws found.
Compliance and Business Implications For sites that collect personal data, unresolved vulnerabilities in CMS software may also carry compliance risk under Singapore's Personal Data Protection Act (PDPA), which requires reasonable security safeguards.
The report recommends businesses adopt HTTPS across their sites, keep WordPress core and plugins current, disable unused XML-RPC functionality, review login-path visibility, restrict access to files like readme.html and wp-cron.php, and run security scans at least quarterly.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.
Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.