WordPress Site Hacked? What to Do: A Calm Recovery Checklist
If your WordPress site has been hacked, take a breath: here is a clear, practical plan to contain the damage, clean it up, and stop it from happening again.
By Nathan Cross, Co-Founder, Network & Security Engineering·
WordPress Site Hacked, What to Do First: Confirm It Is Real
If your WordPress site has been hacked, knowing what to do starts with confirming it is a real compromise and not just a glitch. A white screen, a billing lapse, or a plain plugin conflict can look alarming and yet be completely harmless. Before you panic and start deleting things, look for the genuine warning signs that someone has actually gotten in.
If you spot several of these together, treat it as a real compromise and move to containment right away. When you are not sure, a quick passive external scan can tell you whether your site is serving anything malicious to visitors, without you having to log in or touch a single file.
- Your browser or a Google search result shows a "this site may be hacked" or "deceptive site ahead" warning
- Strange pop-ups, spammy redirects, or pharmaceutical and gambling text appear on your pages, often only for visitors arriving from search
- New admin users you did not create, or you are suddenly locked out of wp-admin
- Unfamiliar files in your site folders, or core files that were modified at odd hours
- Your web host emails you about malware, or your site starts sending spam and lands on an email blocklist
- A sudden traffic spike from unusual locations, or pages loading far slower than normal
Contain It: Limit the Damage in the First Hour
Speed matters, but calm matters more. The goal of containment is simple: stop the attacker from doing further harm, and protect your visitors and your data while you work out what happened. You are not cleaning yet, you are closing the doors.
Work through these steps in order. If you are not comfortable doing them yourself, this is a perfectly good moment to call for help rather than risk making things worse under pressure.
- Put the site into maintenance mode or take it temporarily offline so visitors are not exposed to malicious code
- Change every password: WordPress admin, hosting and cPanel, the database, FTP and SFTP, and the email account tied to your logins
- Force a logout of all active sessions so any stolen logins stop working immediately
- Rotate any API keys or secrets stored in the site, and disable admin accounts you do not recognise
- Tell your web host: many can isolate the account, take a snapshot, and point you to their own cleanup tools
- Pause checkout or form submissions if customer or payment data could be exposed while you investigate
Assess the Scope Before You Start Deleting
Resist the urge to delete files at random. First, understand how deep the problem goes. Check when files were last modified, review your access and error logs for the window when trouble started, and note which user accounts, plugins, and themes look out of place.
Pay special attention to plugins and themes, because that is almost always the way in. Plugins account for roughly 96% of WordPress vulnerabilities, with only a handful ever found in WordPress core itself (Patchstack). The scale is not small either: Patchstack recorded nearly 8,000 new WordPress vulnerabilities in 2024, about a 34% increase on the year before (Patchstack, via SecurityWeek). An out-of-date or abandoned plugin is the single most likely entry point, so make a short list of what changed, what looks foreign, and where an attacker may have left a back door.
Clean the Site, or Restore From a Known-Good Backup
The cleanest path is almost always to restore from a backup taken before the compromise. If you have a verified clean backup, restore it, then immediately apply the hardening steps below so you are not reinfected through the very same hole within days.
If you have no clean backup, the site has to be cleaned by hand or with a reputable malware tool. That means removing injected code, replacing WordPress core, your theme, and your plugins with fresh copies from official sources, and carefully hunting down the hidden back doors that let attackers come straight back.
- Reinstall WordPress core, your active theme, and all plugins from clean, official downloads rather than patching the infected files
- Scan the database for injected scripts, spam content, and rogue admin users
- Remove any unknown files, especially anything executable sitting in the uploads folder, and delete leftover back doors
- Confirm the site is genuinely clean before bringing it back online, then submit a review request to Google if your site was flagged
Harden So It Does Not Happen Again
Recovery is only half the job. A site that gets cleaned but not hardened is often hit again within weeks, because the weakness that let the attacker in is still sitting there until you close it. Most small-business hacks are opportunistic: automated bots scanning for a known vulnerable plugin, not a hacker singling you out by name.
Small businesses are squarely in the firing line. In Verizon's 2025 Data Breach Investigations Report, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organisations (Verizon 2025 DBIR). The good news is that a handful of solid habits, most of them recommended in the official WordPress hardening guide (WordPress.org), dramatically lower your odds of being an easy target.
- Keep WordPress core, plugins, and themes updated, and delete anything you no longer use
- Turn on two-factor authentication for every administrator account
- Use strong, unique passwords and a password manager across the whole team
- Set up reliable, off-site backups, and actually test that they restore
- Add HTTP security headers and keep your TLS certificate valid and current
- Schedule regular scans so new problems surface early, not after the next incident
When to Bring in a Professional
Cleaning a hacked site safely takes time and a careful eye, and one missed back door means the whole mess comes back. If the site handles customer or payment data, if you cannot find the source, or if you simply do not have the hours to do it properly, get help rather than guess.
CyberBadger is an owner-operated IT and cybersecurity team based in Hamilton and Burlington, serving Hamilton, Burlington, Ancaster, Stoney Creek, Oakville, Dundas, Grimsby, Niagara Falls, Milton, and Flamborough on-site, and remotely across Canada. We can confirm what happened, clean it properly, and harden it so it stays fixed. Reach us at (289) 796-8900.
Confirm It Is Clean, Then Lock It Down
Run a free BadgerScan to check your site from the outside for malware signs, exposed files, and weak security, then see exactly what to fix. If you would rather have a local Canadian team handle the cleanup and hardening, CyberBadger can help on-site or remotely.
Run a free security scanFrequently asked questions
How do I know if my WordPress site is really hacked?
Look for clear signs: browser malware warnings, spammy pop-ups or redirects, admin users you did not create, recently modified core files, or your host flagging malware. A passive external scan can confirm whether your site is serving anything malicious to visitors, without you having to log in or touch the site itself.
My WordPress site is hacked, what should I do first?
Stay calm and contain it. Put the site into maintenance mode or take it temporarily offline so visitors are not exposed to malicious code, then change every password, force a logout of all sessions, and tell your web host before you begin any cleanup.
Can I just restore a backup to fix a hacked WordPress site?
Restoring a verified clean backup from before the compromise is the cleanest fix, but it is not enough on its own. You must also harden the site with updates, two-factor authentication, and strong passwords, or the same weakness will let attackers straight back in. Plugins account for roughly 96% of WordPress vulnerabilities (Patchstack), so updating and removing unused plugins matters most.
How do I stop my WordPress site from getting hacked again?
Keep core, plugins, and themes updated, remove anything unused, enable two-factor authentication, use strong unique passwords, keep tested off-site backups, and scan regularly. Because small businesses are heavily targeted (Verizon 2025 DBIR), closing the obvious gaps is what keeps the automated bots out.