Outdated plugins drive 74% of WordPress vulnerabilities
One-third of the sites had three or more outdated plugins.
Sites with three or more outdated plugins accounted for 74.2% of confirmed WordPress vulnerabilities found across 102 Singapore business websites, according to Equinet Academy.
Its Singapore WordPress Website Cybersecurity Study found that 34 websites, or 33.3% of the sample, had at least three outdated plugins. These sites accounted for 1,375 of the 1,853 confirmed vulnerabilities detected.
The findings show that vulnerability exposure was concentrated amongst websites with larger plugin maintenance gaps, rather than being distributed across the sample.
Keeping WordPress core updated did not eliminate exposure to plugin vulnerabilities. Of the 48 websites running a current WordPress core version, 29, or 60.4%, still had confirmed plugin vulnerabilities. A further 25, or 52.1%, had at least one outdated plugin.
“Updating WordPress core is important, but it does not address vulnerabilities introduced through third-party plugins,” the analysis said.
Outdated WordPress core and plugins also appeared together across most websites running an outdated core version. Of the 41 websites with an outdated WordPress core, 39, or 95.1%, also had outdated plugins.
Those 39 websites accounted for 1,283 confirmed vulnerabilities, or 69.2% of all vulnerabilities detected in the study.
The supplementary analysis said regular updates, plugin management and ongoing website maintenance remain important components of reducing exposure.
The Singapore WordPress Websites Cybersecurity Study examined 102 publicly accessible WordPress websites operated by Singapore-based businesses through passive automated scanning.