
How to recover a hacked WordPress website?
To recover a hacked WordPress website, you need to contain the damage, take a snapshot for investigation, reset every password, replace WordPress core, themes, and plugins with clean copies, remove malicious code from your uploads and database, and then close the hole the attacker used to get in. If you have a clean backup from before the hack, restoring it can speed things up, but you still need to find and fix the original vulnerability or the site will be reinfected.
Discovering that your site has been hacked is stressful, but a methodical approach works far better than panicked clicking. This guide walks you through the full recovery process, from spotting the signs of a compromise to cleaning files and the database, removing blocklist warnings, and hardening the site so it doesn't happen again. It focuses on recovery; for general prevention, a dedicated WordPress security guide goes deeper.
Signs Your WordPress Site Has Been Hacked
Hacks aren't always obvious. Common signs include:
- Unexpected redirects: Visitors, especially those arriving from search engines or on mobile, are sent to spam, gambling, or scam sites.
- Browser or search warnings: Chrome shows a red "Dangerous site" warning, or Google search results display "This site may be hacked."
- Spam in search results: Searching
site:yourdomain.comreveals pages you never created, often in other languages or selling pharmaceuticals. - Unknown admin users: New administrator accounts appear under Users > All Users.
- Modified or unfamiliar files: PHP files show up in
wp-content/uploads, or core files have recent modification dates you can't explain. - Host notifications: Your host suspends the account or warns about malware or outgoing spam.
- Sudden performance problems: Unusual CPU usage or bandwidth spikes caused by malicious scripts.
- Defacement: Your homepage is replaced with a hacker's message. This is less common today than silent, profit-driven hacks.
If you see one or more of these, treat the site as compromised until you prove otherwise.
Step 1: Stay Calm and Contain the Damage
Your first priority is to stop the attack from causing more harm to visitors and to your data.
- Put the site in maintenance mode or take it offline: If the site is redirecting visitors to malicious pages, temporarily block public access. Many hosts let you disable a site from the dashboard. You can also restrict access by IP in
.htaccesswhile you work. - Contact your host: Tell them what's happening. Good hosts can confirm the compromise, check server logs, and sometimes help with cleanup. They'll also want to know if your site is part of a wider issue on the server.
- Check other sites on the same account: On shared hosting, one infected site can infect every other site under the same user. Plan to clean all of them.
Here's a simple .htaccess rule that blocks everyone except your own IP address on Apache 2.4. Replace the IP with yours:
<RequireAll>
Require ip 203.0.113.25
</RequireAll>
Remove it once the cleanup is finished.
Step 2: Take a Snapshot Before You Change Anything
It's tempting to start deleting suspicious files immediately, but make a full copy of the hacked site first. That snapshot helps you or a security professional work out how the attacker got in, and it protects you if you accidentally delete something you need.
- Download all files: Use SFTP or your host's file manager to download the entire WordPress directory.
- Export the database: Use phpMyAdmin or WP-CLI.
wp db export hacked-snapshot.sql
tar -czf hacked-files-snapshot.tar.gz /path/to/wordpress
Store these copies somewhere safe and clearly label them as infected. Never restore from them.
Step 3: Reset All Passwords and Keys
Assume every credential connected to the site is compromised. Change them all, from a device you trust:
- Hosting control panel: Your host account password.
- SFTP and SSH: All file access accounts. Remove any accounts you don't recognize.
- Database password: Change it in your hosting panel, then update
DB_PASSWORDinwp-config.phpto match. - WordPress users: Reset passwords for every administrator and editor.
- Email accounts: Especially the one connected to your admin user, since it can be used to reset passwords.
Regenerate WordPress Security Keys
WordPress uses secret keys and salts in wp-config.php to secure login cookies. Replacing them logs out every user, including the attacker, immediately. Get fresh keys from the official generator at https://api.wordpress.org/secret-key/1.1/salt/ and replace the existing block:
define( 'AUTH_KEY', 'put your unique phrase here' );
define( 'SECURE_AUTH_KEY', 'put your unique phrase here' );
define( 'LOGGED_IN_KEY', 'put your unique phrase here' );
define( 'NONCE_KEY', 'put your unique phrase here' );
define( 'AUTH_SALT', 'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT', 'put your unique phrase here' );
define( 'NONCE_SALT', 'put your unique phrase here' );
With WP-CLI, you can regenerate them in one command:
wp config shuffle-salts
Remove Unknown Admin Users
Go to Users > All Users and filter by Administrator. Delete any account you didn't create, attributing its content to a legitimate user if prompted. Attackers sometimes hide users from the dashboard with code, so also check the database directly:
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
Or in SQL, replacing wp_ with your table prefix:
SELECT u.ID, u.user_login, u.user_email, u.user_registered
FROM wp_users u
JOIN wp_usermeta m ON u.ID = m.user_id
WHERE m.meta_key = 'wp_capabilities'
AND m.meta_value LIKE '%administrator%';
Step 4: Scan the Site to Find the Infection
Scanning helps you understand how widespread the infection is and which files have been changed.
Use a Security Plugin
If you can still access the dashboard, install a reputable scanner:
- Wordfence Security: Compares core, theme, and plugin files against the official repository versions and flags known malware signatures.
- Sucuri Security: Offers file integrity monitoring and a remote scanner.
- MalCare: Scans on its own servers, which reduces load on your hosting.
Keep in mind that a scanner running inside a compromised site can be fooled by sophisticated malware. Treat scan results as a starting point, not a guarantee.
Verify Core and Plugin Checksums
WP-CLI can compare your files with the official checksums from WordPress.org:
wp core verify-checksums
wp plugin verify-checksums --all
Any file listed as modified or unexpected deserves a close look. Note that plugin checksums are only available for plugins hosted on WordPress.org, so premium plugins won't be verified this way.
Look for Recently Modified Files
Over SSH, list PHP files changed in the last week or so:
find /path/to/wordpress -type f -name "*.php" -mtime -7 -print
Also look for PHP files inside the uploads folder, which should normally only contain images and documents:
find /path/to/wordpress/wp-content/uploads -type f -name "*.php"
Search for Common Malware Patterns
Malicious code is often obfuscated. These patterns aren't always malicious, since some legitimate plugins use them, but they're worth checking:
grep -rnE "eval\(base64_decode|gzinflate\(base64_decode|str_rot13\(|assert\(\\\$_(POST|GET|REQUEST)" /path/to/wordpress --include=*.php
Step 5: Replace Core, Theme, and Plugin Files With Clean Copies
Rather than trying to clean individual infected files, the most reliable approach is to replace everything you can with fresh copies from trusted sources.
- Reinstall WordPress core: Download the same version from WordPress.org and replace the
wp-adminandwp-includesfolders completely, along with the root PHP files. Don't overwritewp-config.phporwp-content. With WP-CLI:
wp core download --force --skip-content --version=$(wp core version)
-
Check wp-config.php by hand: Compare it against
wp-config-sample.php. Look for unfamiliarincludeorrequirestatements, long encoded strings, or code at the very top or bottom of the file. -
Delete and reinstall every plugin: Don't just update. Delete each plugin folder and install a fresh copy from WordPress.org or the developer's site. With WP-CLI, you can reinstall repository plugins in place:
wp plugin install $(wp plugin list --field=name) --force
- Remove plugins and themes you don't use: Inactive code can still be exploited. Delete it.
- Reinstall your theme: Download a fresh copy from its official source. If you use a child theme, review each file manually, since it contains your own customizations and can't be replaced from a repository.
- Remove nulled software: Pirated "nulled" premium themes and plugins are a very common infection source. Replace them with legitimate licensed copies.
Step 6: Clean the Uploads Folder
The wp-content/uploads folder is a favorite hiding place for backdoors because it's writable and usually never inspected.
- Delete any PHP files you find there: Legitimate uploads almost never include PHP.
- Look for disguised files: Names like
image.php.jpg,.icofiles containing PHP, or unexpected.htaccessfiles in subfolders. - Block PHP execution in uploads: This prevents any backdoor that sneaks back in from running. Create
wp-content/uploads/.htaccesswith:
<FilesMatch "\.(?i:php|phtml|phar)$">
Require all denied
</FilesMatch>
On Nginx, add a rule to your server block instead:
location ~* ^/wp-content/uploads/.*\.(php|phtml|phar)$ {
deny all;
}
Step 7: Clean the Database
Malware doesn't only live in files. Attackers inject spam links, malicious JavaScript, and redirect code into posts, options, and widgets.
Check Key Options
Start with the site URL options, which are sometimes changed to redirect the whole site:
SELECT option_name, option_value
FROM wp_options
WHERE option_name IN ('siteurl', 'home', 'admin_email', 'users_can_register', 'default_role');
Make sure users_can_register is 0 unless you intentionally allow registrations, and that default_role is subscriber.
Search Posts for Injected Scripts
SELECT ID, post_title
FROM wp_posts
WHERE post_content LIKE '%<script%'
OR post_content LIKE '%<iframe%'
OR post_content LIKE '%eval(%';
Some results may be legitimate, like embedded videos or analytics snippets you added yourself. Review each one before removing anything.
Check Options for Suspicious Code
SELECT option_id, option_name
FROM wp_options
WHERE option_value LIKE '%<script%'
OR option_value LIKE '%base64_decode%'
OR option_value LIKE '%eval(%';
Widget content, theme options, and header or footer script settings are common places for injections.
Step 8: Restoring From a Backup Instead
If you have a backup from before the infection, restoring it can be faster than cleaning. Consider it when:
- You know roughly when the hack happened: And your backup predates it.
- You can accept losing recent changes: Content or orders added after the backup will need to be re-added.
Restoring still requires every other step in this guide: resetting passwords, regenerating keys, updating everything, and closing the vulnerability. A restored site with the same outdated plugin will simply be hacked again, often within days.
Step 9: Find and Close the Entry Point
Cleanup is only half the job. You also need to understand how the attacker got in. Common entry points include:
- Outdated plugins or themes: The most common cause. Check whether any of your plugins had publicly disclosed vulnerabilities around the time of the hack. Resources like the Wordfence and Patchstack vulnerability databases are useful here.
- Weak or reused passwords: Brute-force and credential-stuffing attacks against
wp-login.php. - Nulled themes or plugins: Often ship with backdoors preinstalled.
- Compromised hosting accounts: A neighboring site on the same account, or stolen SFTP credentials.
- Insecure file permissions: Files writable by anyone on the server.
Your host's access logs can reveal suspicious POST requests to unusual files or repeated requests to a specific plugin path. Ask your host for them if you don't have direct access.
Once you've identified the likely cause, fix it: update or remove the vulnerable component, enforce strong passwords, and correct file permissions. A typical safe setup is 755 for folders and 644 for files:
find /path/to/wordpress -type d -exec chmod 755 {} \;
find /path/to/wordpress -type f -exec chmod 644 {} \;
chmod 600 /path/to/wordpress/wp-config.php
Some hosts require 640 or 644 for wp-config.php instead of 600, so check with yours if the site stops loading after the change.
Step 10: Remove Blocklist Warnings
If Google flagged your site, visitors may see warnings even after it's clean.
- Open Google Search Console: Add and verify your site if you haven't already.
- Check the Security Issues report: Found under Security & Manual Actions > Security issues. It lists the problems Google detected and sample URLs.
- Request a review: Once everything is clean, click "Request Review" and briefly explain what you fixed. Reviews typically take anywhere from a day to a few weeks.
Also check other blocklists and services your site may be flagged on, such as antivirus vendors or email spam lists if your server was sending spam. Sucuri's free SiteCheck scanner shows common blocklist statuses at a glance.
Step 11: Harden the Site Going Forward
With the site clean, put measures in place to make a repeat much less likely:
- Keep everything updated: Enable automatic updates for plugins you trust, and check for updates weekly.
- Use two-factor authentication: Plugins like Wordfence Login Security or Two Factor add 2FA to admin logins.
- Limit login attempts: Stop brute-force attacks at the door.
- Disable file editing in the dashboard: Add this to
wp-config.phpabove "That's all, stop editing!":
define( 'DISALLOW_FILE_EDIT', true );
- Use a web application firewall: Cloudflare, Sucuri, or Wordfence can block many attacks before they reach WordPress.
- Keep off-site backups: Store daily backups somewhere other than your hosting server, and keep several weeks of history so you can go back before an infection that went unnoticed for a while.
- Monitor file changes: File integrity monitoring alerts you when core or plugin files change unexpectedly.
- Give users only the access they need: Not everyone needs to be an administrator.
When to Hire a Professional
If the malware keeps coming back, if you run an e-commerce or membership site that handles customer data, or if you simply don't have the time, professional cleanup services from companies like Sucuri, Wordfence, or MalCare are worth considering. Many managed WordPress hosts also include malware removal in their plans. If personal data may have been exposed, you may also have legal obligations to notify affected users under laws like GDPR, so get advice specific to your situation.
FAQ: Recovering a Hacked WordPress Site
Look for unexpected redirects, unknown admin users, spam pages in Google results, browser security warnings, or PHP files in your uploads folder. A reputable scanner and a checksum comparison can confirm whether files have been modified.
Restoring a clean backup removes the infection, but not the vulnerability that allowed it. You still need to update or remove the weak component, reset passwords, and regenerate security keys.
Not always. Attackers usually plant backdoors in other places, such as uploads, core files, or the database, so the site can be reinfected even after the original vulnerable plugin is removed.
A straightforward infection on a small site can often be cleaned in a few hours. Complex or recurring infections, large sites, and blocklist reviews can stretch the process over several days.
Recurring infections usually mean a backdoor was missed or the original entry point is still open. Check uploads for PHP files, review wp-config.php, look for hidden admin users, and make sure every plugin and theme is up to date.
If the attacker may have accessed personal data, such as customer details or user accounts, you may have a legal obligation to notify them. Rules vary by country, so check the requirements that apply to you.
It can. Spam pages, malicious redirects, and security warnings hurt rankings and click-through rates. Once the site is clean and Google's review is approved, rankings usually recover over time.
Conclusion
Recovering a hacked WordPress website is a process, not a single click. Contain the damage, take a snapshot, reset every password and security key, replace core, plugins, and themes with clean copies, clean the uploads folder and database, and then find and close the entry point. Finish by requesting a review from Google so visitors stop seeing warnings.
The most important lesson from any hack is that prevention costs far less than recovery. Regular updates, strong passwords with two-factor authentication, a firewall, and reliable off-site backups make your site a much harder target and give you a quick, calm path back if something ever goes wrong again.


