Signs of a hack
- Your pages show strange ads or text.
- Visitors are sent to other websites.
- You cannot log in to your admin area.
- New admin users appear that you did not make.
- Your host or a browser warns about harmful content.
Before you change anything
Take a backup of the hacked site, even though it is dirty. It may help find out what happened. If you have a clean backup from before the hack, find it now. Do not delete anything until you know what you have.
Steps to replace the hacked files
- Log in to your client area and open cPanel.
- Change your cPanel password to a new strong one.
- Open File Manager and go to your site folder, often
public_html. - Download a fresh WordPress copy from wordpress.org on your computer and unzip it.
- In File Manager, delete the
wp-adminandwp-includesfolders. - Upload the fresh
wp-adminandwp-includesfolders from the new copy. - Replace the loose files in the main folder with fresh ones. Do not replace
wp-config.phpor thewp-contentfolder. - Open
wp-config.phpand look for odd code you do not recognize. Remove it with care.
Clean wp-content
- Open
wp-content, thenplugins.
- Delete any plugin you do not use or do not know.
- Reinstall the plugins you need from the official WordPress directory.


- Do the same for themes in
wp-content/themes. - Check
wp-content/uploads. Delete any PHP files there. Pictures should not be PHP.
Lock the door again
- Log in to WordPress. Go to Users and delete admin users you do not know.
- Change every user's password.
- Go to Dashboard, then Updates and update everything.
- Install a security plugin and run a scan.

- Scan your own computer for viruses.
Tip: If you feel unsure, open a support ticket and ask for help. Restoring a clean backup is often the easiest way.
Quick recap
- Back up first, and change your passwords.
- Replace the core WordPress folders with fresh ones.
- Clean plugins, themes and uploads.
- Remove unknown users and update everything.