Fixing a Hacked Site
Recovering a hacked WordPress site involves more than removing the first suspicious file or user. The investigation needs to identify affected files and accounts, remove unauthorised access and address how the compromise happened.
Document what you can see
- Record warnings, redirects, unfamiliar content and the time they appeared.
- Save relevant hosting, firewall and WordPress security alerts.
- Note recent plugin, theme, user or hosting changes.
- Create a copy of the affected site before cleanup when it is safe to do so.
Protect visitors and regain control
- Restrict the site appropriately if it is exposing harmful content or customer data.
- Use a clean device to secure administrator email, hosting, registrar and WordPress access.
- Review administrator accounts, active sessions and access methods.
- Identify changed files, database entries, scheduled tasks and server rules.
- Replace affected WordPress core, theme and plugin code from trusted sources.
- Remove unauthorised access and rotate credentials again after the environment is clean.
Prevent the site being compromised again
Update supported software, remove unused components, correct vulnerable configuration and review logs for the original entry point. Test the website and monitoring before returning it to normal use. A backup can help recovery, but restoring without closing the entry point can allow reinfection.
Read Website Hacking and Malware for wider incident guidance. Shield Pro includes malware prevention and removal, or you can submit a Fix Request for developer help.
Common questions
Frequently Asked Questions
Can I clean a hacked site by deleting one suspicious file?
That may remove one symptom, but another file, user, scheduled task or exposed credential may still provide access. The full installation and entry point need review.
Should I restore the latest backup?
Use a restore point known to predate the compromise, while accounting for later content or orders. The vulnerability and exposed credentials must still be addressed.
When should passwords be changed?
Secure critical accounts when regaining control, then rotate potentially exposed credentials again after the site and access devices are clean.
Can BugShield clean a hacked WordPress site?
Yes. Shield Pro includes malware prevention and removal, and a Fix Request can be used when you need a developer to investigate a compromised site.