Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

What to Do When Your WordPress Site Is Hacked

If someone has broken into your site, stay calm. This guide shows steps to clean it and get a safe copy back.

WordPress2 min read18 steps4 screenshots

Signs of a hack

  • Your pages show strange ads or text.
  • Visitors are sent to other websites.
  • You cannot log in to your admin area.
  • New admin users appear that you did not make.
  • Your host or a browser warns about harmful content.

Before you change anything

Take a backup of the hacked site, even though it is dirty. It may help find out what happened. If you have a clean backup from before the hack, find it now. Do not delete anything until you know what you have.

Steps to replace the hacked files

  1. Log in to your client area and open cPanel.
  2. Change your cPanel password to a new strong one.
  3. Open File Manager and go to your site folder, often public_html.
  4. Download a fresh WordPress copy from wordpress.org on your computer and unzip it.
  5. In File Manager, delete the wp-admin and wp-includes folders.
  6. Upload the fresh wp-admin and wp-includes folders from the new copy.
  7. Replace the loose files in the main folder with fresh ones. Do not replace wp-config.php or the wp-content folder.
  8. Open wp-config.php and look for odd code you do not recognize. Remove it with care.

Clean wp-content

  1. Open wp-content, then plugins.
    Screenshot: Open wp-content , then plugins .
  2. Delete any plugin you do not use or do not know.
  3. Reinstall the plugins you need from the official WordPress directory.
    Screenshot: Reinstall the plugins you need from the official WordPress directory.
    Screenshot: Reinstall the plugins you need from the official WordPress directory.
  4. Do the same for themes in wp-content/themes.
  5. Check wp-content/uploads. Delete any PHP files there. Pictures should not be PHP.

Lock the door again

  1. Log in to WordPress. Go to Users and delete admin users you do not know.
  2. Change every user's password.
  3. Go to Dashboard, then Updates and update everything.
  4. Install a security plugin and run a scan.
    Screenshot: Install a security plugin and run a scan.
  5. Scan your own computer for viruses.
Tip: If you feel unsure, open a support ticket and ask for help. Restoring a clean backup is often the easiest way.

Quick recap

  • Back up first, and change your passwords.
  • Replace the core WordPress folders with fresh ones.
  • Clean plugins, themes and uploads.
  • Remove unknown users and update everything.