Back to articles

What to Do If Your WordPress Site Has Been Hacked

Computer screen displaying a hacked system warning

Finding out that your WordPress site has been hacked is a horrible moment. You may see strange redirects, spam pages, unfamiliar users, security warnings, defaced content or emails from customers saying something is wrong.

The important thing is not to panic and not to start deleting things blindly. A hacked site can usually be recovered, but the order of work matters.

Take the site seriously, even if it still loads

Not every compromise is obvious. Some attackers add hidden spam pages, malicious scripts, backdoors or redirects that only appear for search engines and first-time visitors.

If you suspect a hack, treat it as real until you have checked properly. A compromised site can damage customer trust, search visibility and email reputation, so it is worth acting quickly.

Secure your access first

Start with the accounts that control the site. Change WordPress administrator passwords, hosting control panel passwords, FTP or SFTP passwords, database passwords and any connected email accounts that may have been exposed.

Use strong, unique passwords and enable two-factor authentication where available. Check WordPress users and remove any administrator accounts you do not recognise.

If you work with a developer or hosting support team, tell them what you have changed so they do not lose legitimate access halfway through the clean-up.

Take a backup before cleaning

This can feel backwards, but it is useful to take a backup of the compromised site before cleaning it. That backup can help identify how the attacker got in and preserve evidence if you need to investigate.

Do not restore that backup as your clean version. Keep it separate and clearly labelled.

Scan the files and database

Use a reputable security tool or ask your hosting provider to scan the account. The clean-up may involve removing injected code, deleting unknown files, replacing modified WordPress core files and checking the database for spam content or malicious links.

Be careful with manual clean-ups. Malware often hides in files that look almost legitimate. Attackers may also leave backdoors so they can return later.

Update everything

Once the site is under control, update WordPress core, plugins and themes. Remove anything unused, abandoned or suspicious.

If a plugin or theme caused the vulnerability, replacing it may be safer than simply updating it. Nulled or pirated plugins and themes should be removed completely, even if they appear to work.

Check search and user-facing damage

After cleaning, check the public site carefully. Look for spam pages, unexpected redirects, unfamiliar scripts, odd search snippets and warnings in browser or search tools.

If search engines have flagged the site, you may need to request a review once the problem is fixed. If customer data may have been exposed, take proper advice on your responsibilities before making assumptions.

Close the gap that let it happen

Cleaning the site is only half the job. You also need to reduce the chance of it happening again.

That means keeping software updated, using fewer and better plugins, limiting admin access, adding two-factor authentication, reviewing file permissions, using security monitoring and keeping reliable off-site backups.

A hacked WordPress site is stressful, but it can also be a useful warning. Once the site is clean, use the moment to build better maintenance habits rather than simply going back to business as usual.