What to Do If Your WordPress Site Gets Hacked

It usually starts with a phone call or an email.

“My website is sending people to some weird site.” Or, “Google says my site is dangerous.” Or my favorite, “There’s a bunch of pages on my site about things I definitely don’t sell.”

If you’re reading this because it just happened to you, take a breath. A hacked WordPress site is stressful, but it’s fixable. I’ve cleaned up more of these than I can count, and the process is pretty much the same every time.

Here’s the plan, step by step.

First, don’t start deleting things. It’s tempting to rip out every plugin and start over. Slow down. You’ll want a copy of the hacked site to figure out how they got in, and you don’t want to make things worse.

Step 1: Confirm it’s really a hack

Some “hacks” turn out to be a broken plugin or an expired domain. Look for the real signs:

  • Visitors get redirected to spammy or scammy sites, sometimes only on mobile or only from Google.
  • Google shows “This site may be hacked” in search results, or Chrome shows a red warning page.
  • Strange pages or posts you didn’t create show up in Google (try searching site:yourdomain.com).
  • Admin users you don’t recognize appear under Users.
  • Your host has suspended the account or emailed you about malware.
  • You can’t log in, and your password reset doesn’t work.

If you’re seeing one or more of these, assume the worst and keep going.

Step 2: Lock the doors

Before you clean anything, cut off the attacker’s access. Change these passwords, using new, unique, strong ones:

  1. Your hosting account (cPanel, FastPanel, or whatever your host uses)
  2. Every WordPress administrator account
  3. SFTP/FTP accounts
  4. The database password (update wp-config.php to match)
  5. The email account tied to your WordPress admin

Then turn on two-factor authentication anywhere you can. If someone has your email, they can reset everything else.

Step 3: Make a backup of the hacked site

Yes, really. Back up the infected site, files and database, before you change anything. Label it clearly as hacked so nobody restores it by accident.

Why? If the cleanup goes sideways, you have something to fall back on. And it helps you (or whoever you hire) figure out how they got in.

Step 4: Decide: restore or clean?

Option A: Restore from a clean backup

If you have a backup from before the hack, this is often the fastest fix. The catch is knowing when the hack actually started. Hackers often sneak in weeks before anything visible happens.

If you restore, immediately update WordPress, every plugin and every theme. Otherwise, you’ve just restored the same hole they came in through.

Option B: Clean it yourself

No clean backup? Here’s the general process:

  • Scan the site. Use a security plugin like Wordfence, your host’s malware scanner, or a free outside scan like Sucuri SiteCheck. These point you to infected files.
  • Replace WordPress core. Reinstall a fresh copy of WordPress from Dashboard → Updates → Re-install. This replaces core files without touching your content.
  • Replace plugins and themes with fresh copies. Delete them and reinstall from the official source. Remove anything you don’t use. Abandoned plugins are a favorite way in.
  • Check the uploads folder. wp-content/uploads should hold images and documents, not .php files. A PHP file in there is almost always a backdoor.
  • Check the usual hiding spots. Look at wp-config.php, .htaccess, and the wp-content/mu-plugins folder for code you didn’t put there.
  • Remove unknown admin users.
  • Reset your security keys. Replace the salts in wp-config.php with fresh ones from the WordPress salt generator. That logs everyone out, including the attacker.

Replacing the core files is the step that makes most people nervous, so here’s a video where I walk through exactly how to do it:

Then scan again. Keep going until it comes back clean.

Here’s the hard truth: a lot of hacks leave backdoors behind so the attacker can get back in later. If you clean the visible damage but miss the backdoor, you’ll be doing this again next month. If you’re not confident you got everything, this is the time to call in help.

Step 5: Tell Google you’re clean

If Google flagged your site, the warning won’t go away on its own.

  1. Open Google Search Console.
  2. Go to Security & Manual Actions → Security issues.
  3. Review what Google found, confirm it’s fixed, and click Request review.

Reviews usually take anywhere from a day to a few days. If your host suspended you, contact them too, and let them know what you cleaned.

Step 6: Make sure it doesn’t happen again

Most hacked sites I see got in one of three ways: outdated plugins, weak or reused passwords, or abandoned plugins nobody remembered were installed. So:

  • Keep everything updated. Follow my Monthly WordPress Maintenance Checklist.
  • Use strong, unique passwords and two-factor authentication.
  • Delete plugins and themes you’re not using.
  • Add a firewall, through your host, Cloudflare, or a security plugin.
  • Keep automatic off-site backups, so next time restoring is an easy option.

Fixing a hacked WordPress site: the short version

  1. Confirm it’s a hack
  2. Change every password and turn on two-factor
  3. Back up the hacked site (label it!)
  4. Restore a clean backup, or clean it file by file
  5. Request a review in Google Search Console
  6. Harden the site so it doesn’t happen again

If you want to go deeper on prevention, that’s exactly what my book WordPress Security Made Simple: The No-Nonsense Guide to Protecting Your WordPress Site covers.

And if your site is hacked right now and you’d rather hand it to someone who’s done this many times, that’s what WP Just Fix It is for.

Similar Posts