WordPress Hacks are escalating: What Thailand Businesses need to know

A look at wp2shell and the WordPress 7.0.3 security release, and what both mean for Bangkok & Thailand businesses running WordPress.

WordPress Security Thailand

If you run a WordPress site in Bangkok or anywhere else in Thailand, the last three weeks should have your attention. First came wp2shell, a critical exploit chain that let attackers take over WordPress sites with no login required. Then, just last night, WordPress pushed out version 7.0.3 to patch twelve more vulnerabilities at once, including a login-screen flaw serious enough to be rated 8.9 out of 10. Two major security events on WordPress core in under a month is not normal. What connects them is AI, and it changes how seriously site owners here need to take maintenance going forward.

WordPress is the platform behind a huge share of the websites we see across Thailand, Hotels, ecommerce stores, media sites, manufacturers and more. That popularity is exactly why these two releases matter more locally than they might seem at first glance. A widely used platform with a widely available AI-discovered exploit is a bigger target pool and not a smaller one.

wp2shell: An exploit built by AI, not a Person

In mid-July a security researcher at Searchlight Cyber pointed OpenAI’s GPT-5.6 Sol Ultra model at a clean copy of the WordPress core codebase and asked it to hunt for a path from zero access to full remote code execution. He stripped out the changelog and version history so the model couldn’t just diff against known patches, then set it loose with multiple research agents for at least six hours. It found a pre-authentication SQL injection and chained it into full remote code execution. Total time: roughly ten hours. Total cost: about twenty-five dollars.

The result was nicknamed wp2shell and it is not a minor bug. Because it lives in WordPress core rather than a plugin or theme, it affects a huge share of the roughly 500 million sites running WordPress, and it requires nothing from the attacker except network access, no account, no plugin misconfiguration, nothing. WordPress took the unusual step of forcing automatic updates on affected installations, and within days researchers were tracking dozens of proof-of-concept exploits and confirmed active attacks in the wild, with scanning traffic hitting the batch REST API endpoint that the bug lived in.

A vulnerability of this severity, one that in past years might have taken a skilled human researcher weeks, was produced by an AI model for the price of a couple of coffees. That is the shift everyone in hosting and security is now reacting to.

WordPress web2shell exploit explaint

Last night: WordPress 7.0.3 patches 12 more Vulnerabilities

WordPress released version 7.0.3, a security update that patches 12 separate vulnerabilities in one go. According to Search Engine Journal’s coverage of the release, the most serious of the twelve is a pre-authentication cross-site scripting flaw on the login screen, rated high severity at 8.9 out of 10, that can potentially be escalated to remote code execution through social engineering. The official WordPress security advisory notes the fix has been backported all the way to version 4.7, which gives a sense of how long the flaw had been sitting there unnoticed.

The other eleven range from lower-severity issues, several contributor-level stored XSS bugs in core blocks, an information disclosure bug that exposed comments on password-protected posts, a server-side request forgery issue and a privilege escalation bug affecting multisite networks with open registration to more obscure ones like post slug enumeration. None of the twelve had detailed severity write-ups from WordPress itself, which is fairly typical of these releases and part of why site owners tend to underestimate them.

What ties this release back to wp2shell is who found the bugs. Patchstack researchers noted that three weeks after wp2shell dropped, this release patched a dozen more issues reported by Anthropic, pwn_ai, Aikido Security, and other AI-focused security teams, exactly the wave of copycat AI-assisted research he’d predicted once wp2shell made headlines. He also noted that, unlike wp2shell, none of these twelve are mass-exploitable in the same way, and that Patchstack customers received mitigation rules at disclosure.

Why this matters for Thai Businesses running WordPress

WordPress ships security releases regularly and most site owners have learned to shrug them off. That instinct is becoming dangerous. What changed in the last month is that AI models are now capable of doing the kind of deep, patient code auditing that used to require a specialized human researcher and weeks of time, and they can do it for pocket change. That cuts both ways. It means attackers or researchers who sell findings to attackers can find core vulnerabilities faster than ever. It also means the pool of people and now models poking at WordPress core has grown overnight, so expect the pace of disclosures like this to keep climbing rather than settle back down.

This means the gap between “a patch exists” and “sites get exploited” is shrinking. With wp2shell working exploits were circulating within 48 hours of disclosure. A site that waits a week or two to update which used to be a reasonable cadence is now a real liability, especially for hotels, clinics, finance companies and any Thailand business whose site represents them to international clients who won’t wait around for a slow or hacked page to load.

What to actually do about it

  • Confirm your site is running WordPress 7.0.3 (or the equivalent patched version for your branch) right now don’t assume auto-update caught it.
  • Treat an outdated version as an active incident. If you’re on a version older than 6.9.5 or 7.0.2, that’s not routine maintenance given wp2shell targets exactly those versions.
  • Put a Web Application Firewall in front of anything running WordPress. Most of the wp2shell attack traffic was recognizable at the request level before it ever touched PHP.
  • Review your user accounts. Several of the twelve new vulnerabilities require Contributor or Author-level access to exploit and it’s often more than site owners realize they’ve handed out.
  • Keep offsite, tested backups. When RCE is on the table a fast rollback matters more than almost anything else you can do after the fact.

None of this is a one-time fix. It’s a maintenance posture, and it needs to hold up against a threat landscape that is now moving at AI speed instead of human speed.

How we handle this for our Clients in Thailand

At Sierra IT Group, we handle exactly this for our clients across Bangkok & Thailand. Our fully managed WordPress hosting includes hardened server configurations and firewall rules in front of every install we run. Our ongoing WordPress maintenance packages cover core, plugin & theme updates, security monitoring and daily backups, so releases like 7.0.3 get handled the same day rather than sitting in an inbox. If instead your site is already compromised, our malware removal and recovery service team gets it cleaned up and back online fast.

If you want a second set of eyes on your installation, get in touch and we’ll tell you where you stand.

Ready to Start Your Project?

Tell us what you need and we will put together a clear scope and a fixed price. No surprises.

Ready to Start Your Project?

Tell us what you need and we will put together a clear scope and a fixed price. No surprises.

2018 – 2026 Sierra IT Group Co., Ltd. | Sitemap | Privacy Policy

This website uses cookies We use cookies to improve your experience and analyse traffic. By clicking Accept, you consent to our use of cookies under Thailand's PDPA.
Privacy Policy