Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Clean Up a Hacked WordPress Site

This guide helps you take back control of a WordPress site that a hacker changed, and clean its content.

WordPress2 min read15 steps9 screenshots

What is a hacked site?

A hacked site is one where a stranger got in and changed things. They may add spam links, hidden pages, strange files or a redirect to another site. Stay calm. Most hacked sites can be cleaned if you work step by step.

Warning: Cleaning can delete files. Take a backup first, even of the hacked site. Keep it in a safe place for reference. A backup is a saved copy.

Step 1: Change your passwords

  1. Change your hosting account password in the client area at https://secure.hostvento.com/clientarea.php.
  2. Change your WordPress admin passwords. Click Users, then edit each user.
    Screenshot: Change your WordPress admin passwords. Click Users , then edit each user.
  3. Change your FTP password and your database password.
  4. Use long, unique passwords.

FTP is a way to move files between your computer and your hosting account.

Step 2: Check your users

  1. Click Users, then All Users.
  2. Delete any administrator you do not know.

Step 3: Replace the core files

The core files are the main WordPress program files. You can swap them for fresh ones.

  1. Click Dashboard, then Updates.
    Screenshot: Click Dashboard , then Updates .
  2. Click Re-install version.

This replaces core files and keeps your content.

Step 4: Reinstall plugins and themes

  1. Delete all plugins and themes you do not use.
  2. For the ones you keep, delete them and install fresh copies from the official WordPress library.
    Screenshot: For the ones you keep, delete them and install fresh copies from the official WordPress li
    Screenshot: For the ones you keep, delete them and install fresh copies from the official WordPress li
  3. Do not use pirated "nulled" plugins or themes. They are a common way in for hackers.
    Screenshot: Do not use pirated "nulled" plugins or themes. They are a common way in for hackers.

Step 5: Look for bad content

  1. Open Posts and Pages. Look for odd links or text you did not write.
  2. Check the wp-content/uploads folder. It should hold only pictures and documents. Delete any .php file in it.
  3. Open .htaccess and look for redirect rules you did not add.
  4. Check wp-config.php for code you do not know.

Step 6: Run a scan

A security plugin can scan your files for known bad code. Search for a well-known one, such as Wordfence, in Plugins, then Add New. Run a full scan and follow its advice. Hostvento support can tell you whether a server-side scanner is on your plan.

Step 7: Stay safe

  • Keep WordPress, themes and plugins updated.
    Screenshot: Keep WordPress, themes and plugins updated.
    Screenshot: Keep WordPress, themes and plugins updated.
    Screenshot: Keep WordPress, themes and plugins updated.
  • Use two-step login if you can.
  • Make regular backups.

If you cannot clean the site yourself, open a ticket at https://secure.hostvento.com/submitticket.php.

Quick recap

  • Back up, then change every password.
  • Remove unknown users.
    Screenshot: Remove unknown users.
  • Re-install core files, plugins and themes.
  • Check posts, uploads and settings files for bad code.
  • Scan the site and keep it updated.