How to fix a hacked WordPress site: a step-by-step guide

20.08.2026 | Author: Marcin Wiercioch

You visit your website and, instead of your offer, you see adverts for dubious pharmaceuticals. Or Google shows the message “This site may be hacked” next to it. Sound familiar? WordPress infections are one of the most common problems website owners come to us with, and they can almost always be cured. Below we show step by step how to fix an infected website and make sure the problem does not come back.

How do you know your website is infected?

Malicious code rarely announces itself; it often works for weeks before anyone notices. The most common symptoms are:

  • redirects to unknown websites (sometimes only from Google results or only on mobile devices),
  • foreign content in search results: Japanese or “pharmaceutical” phrases attached to your domain (so-called SEO spam),
  • a “This site may be hacked” warning in Google or a red warning screen in the browser,
  • spam sent from your domain and company emails landing in spam folders,
  • a sudden slowdown of the website or a jump in server load,
  • administrator accounts, plugins or files that nobody on the team created.

Step 1: get the situation under control

Before you start deleting anything, secure the area:

  • Make a copy of the current state of the files and the database. It sounds counterintuitive (why back up an infected website?), but if the clean-up goes wrong you will have something to go back to, and a sample of the malicious code will help determine the attack vector.
  • Turn on maintenance mode or temporarily restrict traffic: the fewer visitors reach the infected website, the better for them and for your reputation.
  • Change all passwords: for the WordPress dashboard, FTP/SSH, the database and the hosting panel. The attacker may have captured them.
  • Review the list of users and remove unknown accounts with administrator rights.

Step 2: diagnose the extent of the infection

The basic question is: which files were changed? If you have console access, WP-CLI works great, comparing core and plugin files with the official checksums:

wp core verify-checksums
wp plugin verify-checksums --all

It is also worth searching for recently modified files and classic signatures of malicious code:

find . -name "*.php" -mtime -14 -not -path "./wp-content/cache/*"
grep -rl "eval(base64_decode" --include="*.php" .

Pay special attention to the wp-content/uploads directory, which should not contain any PHP files:

find wp-content/uploads -name "*.php"

Scanners also help with the diagnosis: Wordfence or Sucuri SiteCheck on the application side and the hosting provider’s antivirus scanner on the server side. Remember, though, that a scanner finds known signatures; a clean result does not always mean a clean website.

Step 3: remove the malicious code

Files

The most effective method is not “cutting out” suspicious lines, but replacing everything that can be replaced with clean versions: upload the WordPress core again from wordpress.org, and reinstall plugins and themes from scratch from the official repositories or from the vendors. Only files unique to your website need manual analysis: a custom theme, wp-config.php, .htaccess and the contents of uploads.

Database

Malicious code can survive in the database: check the users table for unknown administrators, review wp_options (especially siteurl, home and options with embedded code), look for injected scripts in post content and for suspicious scheduled tasks (cron). After the clean-up, generate new keys and salts in wp-config.php; this invalidates all active sessions.

Step 4: find the back door and close it

Removing an infection without finding its source is asking for a repeat in two weeks. The vast majority of WordPress break-ins come from one of four causes: an outdated plugin or theme with a known vulnerability, “nulled” premium plugins from illegal sources (they very often have built-in backdoors), weak or leaked passwords, or an infection of a neighbouring website on the same hosting account. Review the server logs from the period of the infection; they usually show the first requests to the malicious file and how the attacker got in.

Step 5: rebuild trust

Once the website is clean: update everything to the latest versions, request a review in Google Search Console (the “Security issues” section), check your domain on spam blocklists and watch the website for a few weeks. If the infection returns, the back door is still open.

How to avoid getting infected again

  • regular updates of the core, plugins and themes (and, with ongoing support, tested before deployment),
  • backups stored off the website’s server, made automatically and tested,
  • two-factor authentication (2FA) for all administrators,
  • keeping the number of plugins to a minimum, since each one is a potential door,
  • a web application firewall (WAF) and file change monitoring,
  • strong, unique passwords from a password manager, without exception.

When to leave the repair to specialists

If the website is an important sales channel, the infection keeps coming back despite the clean-up, or you simply do not feel confident working with the files and the database, do not take the risk. At Okinet we have been repairing infected WordPress websites for years: we remove the malicious code, find the source of the break-in, harden the configuration and take the website under ongoing technical support so that the problem does not return. Get in touch: the sooner you react, the smaller the losses.

Related technologies

Marcin Wiercioch Marcin Wiercioch

full stack developer

Co-founder of Okinet, PHP developer, full stack developer, Linux administrator and technology enthusiast with 20 years of experience. Lately I have been focusing especially on optimising and automating development environments, which makes the web applications we build efficient, secure and easy to develop further.

All articles by this author

Share

Rate this article

Let’s talk
about your project

+48 506 160 480
biuro@okinet.pl

or write to us