954-539-5678Free audit
Menu

Web design · Security

How to recover a hacked WordPress site

Work in this order: contain it, find how they got in, clean everything, close the hole, then ask Google to review the site.

Contain first, clean second

Find the entry point

Stop the reinfection loop

Talk to us

Tell us what you need and we’ll get back to you. Or book a free 30-minute call. Or call 954-539-5678.

The short answer

If your WordPress site has been hacked, fix it in this order. First, take a full backup of the infected site so you have evidence and a fallback. Second, change every password: WordPress admins, hosting, FTP or SFTP, the database and your email. Third, find how the attacker got in, which is usually an outdated plugin or theme, or a stolen admin password. Fourth, clean or replace the files and database, and remove any admin accounts you did not create. Fifth, update everything and close the hole. Finally, if Google has flagged the site, request a review in Search Console.

The order matters. Most sites that get reinfected a week later were cleaned without anyone finding the original entry point. The rest of this guide walks through each step, the signs that tell you how bad it is, and when to hand it to someone else.

Signs your site has been hacked

Some hacks are loud and some are quiet. The quiet ones do more damage because they run for months.

  • Google warnings. “This site may be hacked” in search results, a red browser warning, or an email from Search Console about security issues.
  • Strange search listings. Search site:yourdomain.com and look for pages in Japanese, pharmacy or casino spam you never published.
  • Redirects. Visitors on phones, or visitors arriving from Google, get sent to another site while you see the normal page when you type the address directly.
  • New admin users in Users, or admins whose email addresses you do not recognize.
  • Hosting notices. Your host suspends the account or reports high resource use or outbound spam.
  • Email problems. Messages from your domain land in spam because the server has been sending junk.

Step 1: contain the damage

Before you change anything, protect what you have and stop the harm spreading.

  1. Back up the infected site, both files and database. It feels odd to save a hacked copy, but you may need it to trace what happened, and it protects you if a cleanup goes wrong.
  2. Put the site in maintenance mode if it is redirecting visitors or serving malware. A short outage is better than sending customers to a scam page.
  3. Reset credentials everywhere. Every WordPress administrator, the hosting control panel, SFTP, the database user (then update wp-config.php to match) and any email account tied to admin logins. Change the WordPress security keys and salts in wp-config.php so existing logged-in sessions are thrown out.
  4. Tell your host. Good hosts can show server logs, scan the account and confirm whether other sites on the same account are infected too.

Step 2: find how they got in

The WordPress.org guidance on hacked sites lists forensics, working out how the attackers got in, as a core step, so they cannot use the same route again. Patchstack’s State of WordPress Security in 2026 report found 91% of new WordPress vulnerabilities disclosed in 2025 were in plugins and 9% in themes, with only six in WordPress core. So start there.

  • Plugins and themes. List every installed plugin and theme, active or not, with its version. Check each against a vulnerability database. Anything outdated, abandoned by its developer or installed from a “nulled” (pirated) source is a prime suspect.
  • Logins. Look at access logs for successful admin logins from unfamiliar locations, and for repeated requests to wp-login.php or xmlrpc.php.
  • Recently changed files. Ask your host or use SFTP to sort files by modified date. Malware often sits in uploads, in the theme’s functions.php, or in files named to look like core files.
  • Other sites on the same account. An old test site or forgotten install in a subfolder can infect everything that shares the account.

Step 3: clean the site properly

Cleaning means replacing what you can and inspecting what you cannot replace.

  1. Replace WordPress core. Delete the wp-admin and wp-includes folders and upload fresh copies from WordPress.org for the same version. Keep wp-config.php and wp-content, but read wp-config.php line by line for added code.
  2. Reinstall plugins and themes from the source. Delete each one and install a clean copy from the official repository or the vendor. Remove anything you do not use.
  3. Check uploads. The wp-content/uploads folder should hold images and documents, not PHP files. Any .php file there deserves a hard look.
  4. Inspect the database. Look in the users table for unknown accounts, in the options table for unfamiliar entries that load scripts, and in posts for injected links or script tags.
  5. Check server files such as .htaccess for redirect rules you did not add.
  6. Scan again with a reputable security scanner, and check the site from a phone and from a Google search result, since many redirects only trigger for those visitors.

Restoring a backup can be faster, but only if you know the backup was taken before the infection and you close the entry point straight after. Otherwise you restore the same hole.

Dealing with a hacked site right now and would rather not do this alone? Book a free 30-minute call. We look at what happened and tell you what we’d fix first. No obligation.

Step 4: close the hole and harden

Once it is clean, make the same attack fail next time. The official WordPress hardening guide covers the full list. The essentials:

  • Update WordPress core, every plugin and every theme. Turn on automatic updates for minor releases and for plugins you trust.
  • Require strong, unique passwords and two-step login for every administrator.
  • Cut admin accounts to the people who need them. Editors and authors do not need administrator rights.
  • Disable file editing in the dashboard by adding DISALLOW_FILE_EDIT to wp-config.php.
  • Put a web application firewall in front of the site, either from your host or a security service.
  • Run PHP on a version that still gets security updates. The PHP supported versions page shows which ones do.
  • Keep automated off-site backups, and test a restore so you know they work.

Step 5: repair your reputation with Google

If Google flagged the site, check the Security Issues report in Search Console. It lists the problem type and sample URLs. Once you have fixed every listed issue, request a review from that report. Google’s Security Issues report help says to request a review only once every listed issue is fixed on all pages, because requesting too early can slow down your next review and can get the site marked as a repeat offender. For spam pages that were injected, return a 404 or 410 for those URLs so they drop out of the index.

Also check whether your domain landed on email blocklists, and tell customers if you have reason to think their data or payment details were exposed. If you take payments or store personal data, speak to your insurer and counsel about notification duties. That part is general information, not legal advice.

When to hand it to someone else

A small, clearly understood infection on a simple brochure site is often a DIY job for someone comfortable with SFTP and a database tool. Bring in help when:

  • The site takes payments, logins or form data with personal information.
  • It has been reinfected after a previous cleanup.
  • Google has flagged it and leads have stopped.
  • You cannot find the entry point after an hour or two of looking.
  • Nobody on your team knows the server or hosting setup.

When you hire help, ask them to report what the entry point was and what they changed. A cleanup without that report leaves you guessing.

How JLB USA helps

Our website hosting and support includes constant automated monitoring and malware cleanup, plus the updates that close most of the holes attackers use. If your site needs rebuilding rather than patching, we build custom WordPress websites that you can edit yourself and keep if you ever leave. For ongoing care costs, see our guide to website maintenance costs.

Book it now · Free

Book a free 30-minute call

Pick a time. We look at what you have now with you and tell you what we would change first. No obligation.

Prefer to talk now? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

Can I fix a hacked WordPress site myself?

Often, yes, if the site is simple and you are comfortable with SFTP and a database tool. The hard part is finding how the attacker got in. If you cannot find the entry point, or the site takes payments or personal data, get help.

Will restoring a backup fix a hacked site?

Only if the backup predates the infection and you close the entry point immediately afterwards. Otherwise the same vulnerable plugin or stolen password lets the attacker straight back in.

How long does it take Google to remove a hacked warning?

After you fix the issues and request a review in Search Console, Google reviews the site. Google says most reviews take several days to a few weeks, depending on the issue. Make sure every listed URL is clean before you request the review.

How do WordPress sites usually get hacked?

Most often through outdated or vulnerable plugins and themes, followed by weak or reused admin passwords. Patchstack’s 2026 report found 91% of new WordPress vulnerabilities in 2025 were in plugins.

Should I tell customers my website was hacked?

If there is any chance customer data, logins or payment details were exposed, talk to your insurer and counsel about notification duties. This is general information, not legal advice.

Related services

Want a second opinion on your website or marketing?

Pick a time for my free callCall 954-539-5678