You visit your website and, instead of your offer, you see adverts for dubious pharmaceuticals. Or Google shows the message “This site may be hacked” next to it. Sound familiar? WordPress infections are one of the most common problems website owners come to us with, and they can almost always be cured. Below we show step by step how to fix an infected website and make sure the problem does not come back.
How to fix a hacked WordPress site: a step-by-step guide
20.08.2026 | Author: Marcin Wiercioch
How do you know your website is infected?
Malicious code rarely announces itself; it often works for weeks before anyone notices. The most common symptoms are:
- redirects to unknown websites (sometimes only from Google results or only on mobile devices),
- foreign content in search results: Japanese or “pharmaceutical” phrases attached to your domain (so-called SEO spam),
- a “This site may be hacked” warning in Google or a red warning screen in the browser,
- spam sent from your domain and company emails landing in spam folders,
- a sudden slowdown of the website or a jump in server load,
- administrator accounts, plugins or files that nobody on the team created.
Step 1: get the situation under control
Before you start deleting anything, secure the area:
- Make a copy of the current state of the files and the database. It sounds counterintuitive (why back up an infected website?), but if the clean-up goes wrong you will have something to go back to, and a sample of the malicious code will help determine the attack vector.
- Turn on maintenance mode or temporarily restrict traffic: the fewer visitors reach the infected website, the better for them and for your reputation.
- Change all passwords: for the WordPress dashboard, FTP/SSH, the database and the hosting panel. The attacker may have captured them.
- Review the list of users and remove unknown accounts with administrator rights.
Step 2: diagnose the extent of the infection
The basic question is: which files were changed? If you have console access, WP-CLI works great, comparing core and plugin files with the official checksums:
wp core verify-checksums
wp plugin verify-checksums --all
It is also worth searching for recently modified files and classic signatures of malicious code:
find . -name "*.php" -mtime -14 -not -path "./wp-content/cache/*"
grep -rl "eval(base64_decode" --include="*.php" .
Pay special attention to the wp-content/uploads directory, which should not contain any PHP files:
find wp-content/uploads -name "*.php"
Scanners also help with the diagnosis: Wordfence or Sucuri SiteCheck on the application side and the hosting provider’s antivirus scanner on the server side. Remember, though, that a scanner finds known signatures; a clean result does not always mean a clean website.
Step 3: remove the malicious code
Files
The most effective method is not “cutting out” suspicious lines, but replacing everything that can be replaced with clean versions: upload the WordPress core again from wordpress.org, and reinstall plugins and themes from scratch from the official repositories or from the vendors. Only files unique to your website need manual analysis: a custom theme, wp-config.php, .htaccess and the contents of uploads.
Database
Malicious code can survive in the database: check the users table for unknown administrators, review wp_options (especially siteurl, home and options with embedded code), look for injected scripts in post content and for suspicious scheduled tasks (cron). After the clean-up, generate new keys and salts in wp-config.php; this invalidates all active sessions.
Step 4: find the back door and close it
Removing an infection without finding its source is asking for a repeat in two weeks. The vast majority of WordPress break-ins come from one of four causes: an outdated plugin or theme with a known vulnerability, “nulled” premium plugins from illegal sources (they very often have built-in backdoors), weak or leaked passwords, or an infection of a neighbouring website on the same hosting account. Review the server logs from the period of the infection; they usually show the first requests to the malicious file and how the attacker got in.
Step 5: rebuild trust
Once the website is clean: update everything to the latest versions, request a review in Google Search Console (the “Security issues” section), check your domain on spam blocklists and watch the website for a few weeks. If the infection returns, the back door is still open.
How to avoid getting infected again
- regular updates of the core, plugins and themes (and, with ongoing support, tested before deployment),
- backups stored off the website’s server, made automatically and tested,
- two-factor authentication (2FA) for all administrators,
- keeping the number of plugins to a minimum, since each one is a potential door,
- a web application firewall (WAF) and file change monitoring,
- strong, unique passwords from a password manager, without exception.
When to leave the repair to specialists
If the website is an important sales channel, the infection keeps coming back despite the clean-up, or you simply do not feel confident working with the files and the database, do not take the risk. At Okinet we have been repairing infected WordPress websites for years: we remove the malicious code, find the source of the break-in, harden the configuration and take the website under ongoing technical support so that the problem does not return. Get in touch: the sooner you react, the smaller the losses.



