Discovering that your WordPress site has been hacked can feel overwhelming. If you’re wondering how to fix a hacked site, you’re not alone. Whether running a blog, a business, or an e-commerce site, a hacked WordPress website puts your visitors, data, and reputation at serious risk. However, you can take clear, practical steps to recover your site, secure data, and prevent future attacks.
In this comprehensive step-by-step guide, you’ll learn how to fix a hacked WordPress site, understand the causes behind WordPress hacks, and implement strong website security measures to keep your website safe. We’ll walk through everything in layman’s terms; no tech degree is required.
Why Do WordPress Websites Get Hacked?
WordPress powers over 43.5% of all websites globally, which makes it a frequent target for cybercriminals.

Hackers typically don’t target individual WordPress users, they deploy automated tools that scan thousands of WordPress installations for vulnerabilities. Understanding why hackers breach WordPress websites helps you take proactive steps to secure your site.
Here are the most common causes:
- Outdated software: Failure to update the WordPress core, themes, or plugins leaves known security vulnerabilities exposed, making your site easy to exploit.
- Weak or reused passwords: Using the same password across multiple platforms or simple passwords like “admin123” can allow attackers to gain access through brute force attacks.
- Unsecured themes and plugins: Premium plugins and themes from unofficial sources often contain malicious code or backdoors that hackers use to hijack your site.
- Unused WordPress installations: If left unpatched, old or abandoned WordPress installations on the same server can become an unguarded entry point.
- No security plugin installed: Without a good security plugin monitoring your site, malicious activities like cross-site scripting (XSS), SQL injections, or unauthorized file uploads can go unnoticed.
Hackers target these weaknesses using a combination of brute force, phishing, cross-site scripting, and SQL injection techniques. Their goal is often to steal data, insert spam links, or use your server to launch attacks on other websites. Understanding these risks is the first step in defending your WordPress website against a security breach.
Hire a Pro for Hacked Site Repair
Sometimes, trying to fix a hacked WordPress site on your own can lead to more damage, especially if you’re unfamiliar with PHP, WordPress system files, or server configurations.
Here are signs it’s time to bring in a professional:
- Malware keeps reappearing even after several cleanups.
- You cannot identify the entry point or infected files within your WordPress or database.
- Your WordPress dashboard or login page remains inaccessible despite restoration efforts.
- Ad networks, search engines, or your web host have blacklisted your site, impacting visibility and monetization.
- Your ecommerce site handles sensitive customer data and can’t afford downtime or risk.
Reach out to reputable WordPress security services like Sucuri, MalCare, Wordfence, or vetted developers from platforms. These experts specialize in malware removal, hardening WordPress installations, and recovering compromised websites.
Hiring a pro can save time, prevent data loss, and ensure your site is secure long-term.
Need Help Fixing Your Hacked WordPress Site?
Let WPServices clean, secure, and restore your site; fast and hassle-free.
Recognizing a Hacked WordPress Site: Key Causes
Most WordPress site owners fail to notice a compromise until it causes significant damage. Unlike visible technical issues like broken links, signs of a hacked WordPress website are often subtle. However, prompt recognition is essential to prevent further harm to your site’s security and reputation.
Here are some of the most common red flags:
- Spam redirects, phishing links: Your website suddenly redirects visitors to spam websites or malicious third-party domains without your knowledge.
- Unauthorized content changes: You notice unexpected modifications to your homepage, blog posts, layout, or embedded links that you didn’t make.
- Google warnings, malware flags: Google Search Console or search engines display alerts that your WordPress site may be unsafe or distributing malicious code.
- Hosting account suspension: Your web hosting provider suspends your site or sends you an alert due to suspicious behavior, resource overuse, or detected malware.
- Login issues, blocked access: The WordPress login page becomes inaccessible, or your admin credentials no longer work despite no changes from your side.
- Suspicious admin accounts: New WordPress user accounts, especially those with admin privileges, appear in your dashboard without you creating them.
- Pop-ups, strange ads: Your website starts displaying pop-ups, adult content, fake antivirus warnings, or intrusive ads that drive visitors away.
- Visitor complaints and odd behavior: Visitors report being redirected to strange pages, encountering unsafe content, or receiving antivirus warnings when they visit your site.
These symptoms clearly indicate that hackers have likely compromised your WordPress site and planted malicious code, suspicious files, spammy redirects, or hidden malware. Acting quickly can help reduce data loss, protect your reputation, and restore standard website functionality.
Tips to Fix a Hacked WordPress Site
Here are some of the tried and tested techniques to fix a hacked website:
Tip 1: Initial Response: Stay Calm and Act Quickly
Discovering that your WordPress site is hacked can be stressful, but your immediate reaction is critical to minimizing damage. A quick and methodical response helps you regain control, protect your visitors, and begin recovery. Here’s a step-by-step guide on what to do first when you suspect your WordPress site has been hacked:
Tip 2: Put the Site in Maintenance Mode
If your WordPress site is hacked, the first step is to prevent further damage and protect your visitors.
By placing your website in maintenance mode, you ensure that users are not exposed to malicious content or phishing attempts while you work on recovery.
- Use a plugin like WP Maintenance Mode or SeedProd to display a safe maintenance message.
- Restrict access by editing your .htaccess file to block access to everyone except your IP.
- If you can’t access the WordPress dashboard, use your web hosting control panel or FTP access to manually take the site offline or temporarily rename the main .htaccess file.
Let your users know the site is under maintenance and being fixed. This will help protect your brand reputation and maintain trust.
Maintenance mode also helps search engines avoid indexing malicious content during this time. Keeping the site inaccessible to the public is a vital early step in mitigating damage from a security breach.
Tip 3: Contact Your Hosting Provider
When your WordPress website is hacked, your hosting provider can be critical to your recovery efforts. They typically have security protocols, access to server-level logs, and often tools that you can’t access from the WordPress dashboard.
Here’s how they can help:
- Provide access and server logs to help track how the hacker gained access.
- Temporarily suspend your hacked site to prevent further infection or data loss.
- Identify the type of hack, whether a malware injection, a backdoor, or a malicious redirect.
- Restore a backup from before the infection, if available on their end.
- Offer server-side malware scans or connect you with professional malware removal support.
Immediately notify your hosting support team and explain that your WordPress site is hacked. Ask what server security measures they offer moving forward, such as real-time malware scanning or isolating compromised WordPress installations on the same server.
Tip 4: Back Up Everything
Even though your WordPress site is compromised, taking a full backup before making any changes is crucial. This allows you to analyze the hack in detail later or restore specific parts of the website if needed.
Be sure to back up:
- All WordPress files, including core files, theme and plugin folders, the uploads folder, .htaccess file, wp-config.php, and any suspicious files.
- The WordPress database contains all posts, pages, users, and plugin settings. To export it, use phpMyAdmin or a backup plugin.
To download everything, use your file manager, FTP client, or web hosting control panel. Store the backup in a secure, off-server location. If you hire a professional later, this snapshot can help with forensic analysis, recovery, or support. BlogVault is a recommended WordPress plugin for backups.
Tip 5: Scan Your Site for Malware
To assess the extent of the infection, scan your WordPress website with a reliable malware scanner. These tools analyze your files and database for signs of a hack, such as infected PHP files, malicious code, and spammy redirects.

Popular malware scanners include:
- Jetpack Scan: Easy to use and offers daily automated scans.
- Wordfence: Deep scans core files, themes, and plugins, and consists of a firewall.
- Sucuri Security: Comprehensive malware scanning and monitoring.
- MalCare: Offers one-click malware removal and firewall protection.
After scanning, review the scan results carefully. Look for unfamiliar files, strange code snippets, or modified core WordPress software. These tools can identify malicious content, but you must still decide whether to remove malware manually or automatically, depending on your comfort level and the severity of the infection.
Malware Attacked Your WordPress Site?
Let WPServices eliminate the threat and restore your website’s security; quickly and professionally.
Tip 6: Remove Malware Manually or Automatically
Once you’ve identified that your WordPress site is hacked, the next crucial step is malware removal. Depending on your technical skill level, you can remove the malware manually or use automated tools.
Manual Malware Removal
Manual malware removal gives you complete control but requires technical expertise. You risk breaking your site or missing hidden malicious code if done incorrectly. Follow these steps carefully:
- Replace the core WordPress software: Download a clean copy of the core WordPress software from WordPress.org and overwrite your current installation (excluding the wp-content folder and wp-config.php file).
- Inspect wp-config.php and .htaccess: Hackers often target these files to inject redirects or malicious PHP code. Compare them with clean defaults and remove any suspicious entries.
- Delete or reinstall plugins and themes: Scrutinize those not downloaded from the official WordPress repository or known vendors. Reinstall only the ones you trust.
- Scan the uploads folder: Hackers frequently store malware in the wp-content/uploads directory by disguising it as legitimate files. Look for .php files or anything recently modified.
- Examine the database via phpMyAdmin: Look for suspicious content in your wp_options, wp_posts, and wp_users tables. Malicious code often hides in widget data or user meta.
- Be thorough: Hackers often leave behind hidden backdoors, stealthy PHP files, base64-encoded code, or unknown admin accounts, to regain access even after initial cleanup.
Automated solutions are safer and faster if you’re uncomfortable handling this yourself or if your website’s functionality is critical (like an e-commerce site).
Automated Malware Removal
For most WordPress site owners, using a trusted security plugin or professional service is the safest way to remove malware, especially if you’re not experienced with code.
- Use a good security plugin: Plugins like MalCare, Wordfence, Jetpack Protect, or Sucuri Security can scan, quarantine, and remove malware automatically. They also monitor your site for future hacks.
- Choose host-based malware removal: Many premium hosting providers offer built-in malware scanning and removal, or professional cleanup services. Contact your hosting provider to see if this is included in your plan.
- Follow plugin scan results: Security plugins provide a detailed report of infected files, malicious code, or altered core files. Use this to delete or restore affected files selectively.
Automated tools also help you apply security patches and monitor login attempts to prevent future attacks. After cleanup, always reinstall the latest WordPress core and security plugins.
Tip 7: Reset All Passwords
After cleaning up a hacked WordPress website, resetting all related passwords is essential. Hackers often steal credentials to gain persistent access, even after you’ve removed the malware.
Reset passwords for:
- WordPress admin account: Change the password for all users with admin privileges.
- All WordPress users: Force a password reset to protect all accounts.
- Hosting provider account: Your web hosting control panel (like cPanel or Plesk) is a significant target. Update it immediately.
- FTP/SFTP and database access: If the attacker used FTP access or modified the database, reset those passwords as well.
Use a reliable password manager to generate and securely store strong, unique passwords. Avoid reusing old or weak passwords, and consider enabling two-factor authentication (2FA) for all accounts if possible.
Tip 8: Remove Unused and Suspicious User Accounts
Hackers often create new user accounts with admin privileges to regain access. If not carefully reviewed, these accounts can remain hidden.
To clean up:
- Log in to your WordPress dashboard: Navigate to Users ⟶ All Users.
- Delete unfamiliar accounts: Remove any usernames or email addresses you don’t recognize.
- Check user roles: Downgrade or delete accounts with admin privileges without elevated access.
- Never use “admin” as a username: It’s the first target in brute force attacks. Use a unique, non-obvious username for your WordPress admin account.
Regularly checking your list of users helps prevent future attacks and minimizes potential entry points.
Tip 9: Reinstall Plugins and Themes
Malicious plugins or outdated themes are familiar sources of infection in hacked WordPress websites. Reinstalling them ensures you’re working with clean, secure versions.
Follow these steps:
Delete any plugin or theme that hasn’t been updated recently, or comes from unverified or unauthorized sources.
- Download clean versions: Always get fresh copies of themes and plugins from the official WordPress repository, a verified developer’s site, or a licensed vendor.
- Limit the number of installed plugins: Only keep what’s essential for your site’s functionality. Fewer plugins reduce your attack surface.
- Check for security patches: Ensure that every theme and plugin you reinstall is up to date with the latest security fixes.
Keeping your plugins and themes clean and updated is a significant part of maintaining your site’s security and preventing reinfection.
Tip 10: Clean the Database
Malicious code doesn’t just hide in theme or plugin files; it often infects your WordPress database. Cleaning your database is crucial when recovering a hacked WordPress site, especially if spam links or redirects were injected into posts or site settings.
Use phpMyAdmin (accessible via your web hosting control panel) or a trusted database plugin like WP phpMyAdmin or Adminer. Search for suspicious PHP functions like base64_decode, eval, gzinflate, or preg_replace in your wp_posts, wp_options, or wp_users tables. These functions are often used to obfuscate malicious code.
Look for unexpected content, spammy links, or JavaScript redirects embedded in post content, meta descriptions, or settings fields. It could indicate malicious activity if you find content you don’t recognize, especially in option values or long strings of encoded text.
Before making changes, create a complete backup of your database. If you’re unsure how to proceed or can’t interpret what you see, consult a WordPress security expert to avoid deleting critical data or missing hidden malware.
Tip 11: Request Review from Search Engines
Once you’ve cleaned your hacked WordPress website, restoring your reputation with search engines is essential. If your site was blacklisted or flagged for distributing malware, you’ll need to request a review through Google Search Console.
Start by logging into your Google Search Console account associated with your domain. Navigate to the Security Issues or Manual Actions tab. If malware or security warnings are still present, ensure that all threats and vulnerabilities are resolved before submitting a review.
Once your site is secure and clean of malware, click “Request a Review.” Briefly explain your actions, such as removing infected files, securing your WordPress admin account, or updating your plugins and themes.
Google usually processes malware review requests within a few days to up to two weeks, depending on the severity of the issue and current review volumes. During this time, continue monitoring your WordPress dashboard, search appearance, and user feedback for suspicious behavior.
Also, consider checking where your site may be indexed with Bing Webmaster Tools or other search engines.
Tip 12: Harden WordPress Security
Cleaning a hacked WordPress site is only half the battle; hardening your site’s security helps prevent future attacks. This step ensures that vulnerabilities previously exploited by hackers don’t remain open.
Here are the must-do tasks for hardening your site:
- Install a reliable security plugin like BlogVault, SolidWP, or Sucuri. These plugins offer malware scanning, firewall protection, and brute force prevention.
- Enable a Web Application Firewall (WAF) to block malicious IP addresses and bot traffic.
- Use two-factor authentication (2FA) for all WordPress admin users to add an extra layer of protection.
- Limit login attempts using your security plugin or a tool like Limit Login Attempts Reloaded to block brute force attacks.
- Disable file editing in the dashboard by adding define(‘DISALLOW_FILE_EDIT’, true); to your wp-config.php file.
- Block PHP execution in vulnerable folders like /wp-content/uploads/ using .htaccess rules.
- Check error logs and server logs regularly for suspicious activity, login attempts, or unauthorized file changes.
- Install an SSL certificate to encrypt all data exchanged with your site. This is crucial for e-commerce sites and login pages.
These steps drastically reduce the risk of future hacks and help protect your WordPress system files.
Tip 13: Set Up Regular Backups
Having a reliable backup strategy is non-negotiable. If your WordPress site is hacked again or something goes wrong during an update, a backup can save you hours of work and potential data loss.
Start by installing a backup plugin like UpdraftPlus, BlogVault, or SolidWP. These tools allow you to schedule automatic backups daily or weekly, depending on your content update frequency.
Ensure your backups include the whole site: WordPress files, database, themes, plugins, uploads folder, and configuration files like wp-config.php. Avoid storing backups on the same server if your server gets compromised, your backups might too. Instead, use cloud storage solutions like Google Drive, Dropbox, or Amazon S3.
Also, test your backup restoration process. A backup is only helpful if you can restore it quickly and correctly.
Setting up a solid backup system means you’ll never have to start from scratch again if your WordPress website experiences a security breach, data corruption, or malware infection.
Tip 14: Delete Old or Unused WordPress Installations
Old or unused WordPress installations on the same hosting account are a security risk. These forgotten sites often run outdated software and are rarely updated or monitored, making them easy targets for attackers.
Log in to your web hosting control panel (such, cPanel or Plesk) and look through your root directory. Check for folders with names like /oldsite/, /backup/, or /testsite/. If these are running outdated versions of WordPress, delete them if they’re no longer in use.
Also, look inside the MySQL Databases section to identify and remove old database tables related to these unused installations. Remember to clean out the wp-content folders, installed plugins, and unused themes tied to inactive sites.
Each unused installation adds another entry point for hackers. Deleting them significantly reduces the attack surface and focuses your security efforts on your leading WordPress site.
Tip 15: Educate Your Team and Monitor Activity
Securing your site isn’t a one-person job; your team needs to understand how their actions impact your site’s security. Human error is one of the most common causes of WordPress hacks.
Here’s how to train and protect your team:
- Teach team members to recognize phishing emails and avoid clicking suspicious links.
- Instruct them to only install WordPress plugins and themes from trusted, official sources.
- Ensure they understand the importance of updating WordPress core, plugins, and themes.
Also, set up tools to monitor ongoing site activity:
- Use an activity log plugin like WP Activity Log to track changes in content, settings, or user roles.
- Set up email alerts for unusual login attempts or failed logins.
Review server logs and user activity reports regularly for signs of unauthorized access or file changes.
Encouraging security awareness and monitoring admin activity can help protect your WordPress website from external threats and internal errors.
Conclusion
Fixing a hacked WordPress website can be stressful, but recovery is possible with the proper steps. Once your site is clean, strengthen its security to prevent future attacks. Regular updates, strong passwords, and proactive security measures go a long way.
Whether you manage a personal blog or a large e-commerce site, protecting your website and its visitors should always be a top priority.
Stay safe, stay updated, and don’t let hackers win.


