
If you’ve read our last few posts, you’ve seen the pattern: wp2shell, then WordPress 7.0.3 patching twelve issues, then 7.0.4 closing another remote code execution hole days later. What we haven’t covered yet is what actually happens on the other side of that, when one of those vulnerabilities, or a weak password, or an outdated plugin, actually gets exploited on a real site. We’ve cleaned up enough of these for clients across Thailand to know the pattern well, and it rarely looks the way people expect.
What a hacked WordPress site actually looks like
It’s almost never as obvious as a defaced homepage. In one case we handled for a manufacturing client here in Thailand, the site looked completely normal to every visitor. What was actually happening was a fake plugin, dressed up to look like a legitimate charting or analytics tool, quietly force-loading itself on every page through a core WordPress file. It was injecting spam content and redirect scripts aimed at gambling and casino keywords, the kind of thing designed to hijack a trusted domain’s search authority rather than deface it. The business owner had no idea until Google started flagging the site in search results.
That’s the more common pattern than most people expect. Signs worth taking seriously include: Google Search Console showing a manual action or security issue, browsers showing a red “deceptive site” warning, strange pages appearing in Google for keywords that have nothing to do with your business, a sudden and unexplained traffic spike or drop, unfamiliar admin users in your WordPress dashboard, or your hosting provider emailing you about “abuse” or suspending your account outright.
How attackers actually get in
Almost every hack traces back to one of a small number of doors being left open: an outdated plugin or theme with a known vulnerability, a weak or reused admin password, an old WordPress core version that missed a security release, or in some cases a plugin that looked legitimate but was never what it claimed to be. This is exactly why the pace of releases we’ve covered recently matters, wp2shell and the string of point releases that followed it exist because these doors keep getting found, and every day a site goes unpatched is a day that door stays open to anyone scanning for it.
Why “just delete the plugin” doesn’t actually fix it
This is the mistake we see most often. A site owner notices something wrong, deletes the suspicious plugin or file, and considers the problem solved. It usually isn’t. A real compromise typically leaves more than one way back in, a hidden admin account, a scheduled task, a modified core file, or a backdoor sitting in the uploads folder disguised as an image. Removing the obvious symptom without finding everything else means the same infection, or a new one using the same door, tends to come back within days or weeks. We’ve seen sites get “cleaned” three or four times by well-meaning owners before the actual source was finally found.
What to do in the first hour if you think you’ve been hacked
- Don’t panic-delete things. Removing files before you know what’s infected can destroy evidence of how the attacker got in, which makes it more likely to happen again.
- Check Google Search Console for manual actions or security issues under the Security & Manual Actions section, it’s often the first place a hack gets confirmed.
- Change your WordPress admin, hosting, and FTP/SFTP passwords immediately, from a device you trust.
- Take a full backup of the site as it currently stands before making any changes, even an infected backup is useful for diagnosis.
- Get someone who does this professionally involved quickly. Every hour a compromised site stays live is an hour it can keep spreading, keep getting flagged, and keep losing the trust of anyone who visits it.
The real cost of leaving it
A flagged site doesn’t just look bad, it actively loses money the longer it stays that way. Google Safe Browsing warnings turn visitors away before they ever reach your homepage. Hosting providers will suspend accounts outright if abuse reports come in. For a hotel, an ecommerce store, or any business in Thailand where the website is doing real work, generating bookings, processing orders, representing the brand to international clients, every day this sits unresolved is a day of lost revenue and trust that doesn’t come back automatically once the malware is gone.
How we handle recovery for our Clients in Thailand
At Sierra IT Group, website malware removal is handled by our in-house security team in Bangkok, not outsourced, not templated. We scan the full site to find every infected file, backdoor and compromised database entry, remove it completely, patch the vulnerability that let it in in the first place, and handle Google Safe Browsing and blacklist removal so the warnings actually come down. Most sites are cleaned and back online within 24 to 48 hours, and every recovery comes with a report on exactly what was found, what was fixed, and what changed to stop it happening again. If you think your site might be compromised right now, get in touch and we’ll start the same day.
