My WordPress site was hacked. What do I do now?

  • security
  • hacked
  • malware
  • passwords
  • backups

Updated

If your WordPress site has been hacked, work in this order: lock the attacker out, get a clean copy of the site back, close the hole they came in through, then ask Google to clear any warning. Most hacks come through a stolen or guessed password or an out-of-date plugin, and most sites recover fully.

Signs a site has been hacked

  • Pages redirect to other sites, often only for visitors arriving from Google or on phones.
  • Google search results show spam titles (pharmacy, casino, foreign-language shops) for your pages.
  • The browser or Google shows "Deceptive site ahead" or "This site may be hacked".
  • Admin accounts you don't recognize appear under Users.
  • Your host suspends the site or emails about malware or spam sending.

Some of these have innocent causes, so check before you change anything. A site that won't load at all is a different problem: see Website down? What to check first.

1. Lock the attacker out

  1. Change the passwords for your hosting account, your domain registrar, and every WordPress Administrator. Use long, unique passwords, ideally from a password manager.
  2. Go to Users and delete any account you don't recognize, especially Administrators. Give their content to a real user when WordPress asks.
  3. Change any other passwords that reach the site: SFTP or FTP, the database, and the email account that receives password resets.

2. Tell your host

Contact your host's support. Many hosts scan for malware, can show which files changed and when, and keep backups they can restore. Ask whether the attack reached other sites on the same account.

3. Restore a clean copy

The quickest clean fix is to restore a backup from before the hack. Check the backup's date against the first sign of trouble, then restore it from your host or backup service.

You'll lose changes made since that backup, such as new posts, form entries, and orders. Note them before restoring and re-enter them afterward.

If there's no clean backup, the site has to be cleaned file by file and in the database. That's specialist work, because a missed backdoor lets the attacker straight back in.

4. Close the hole

  1. Update WordPress, every plugin, and the theme under Dashboard → Updates.
  2. Delete plugins and themes you don't use. Deactivated plugins can still be attacked.
  3. Remove any "free" copies of paid plugins downloaded from unofficial sites. They're a common way in.
  4. Give each person the lowest role that lets them do their job. See Manage WordPress users and roles.
  5. Turn on two-factor login if your site or a security plugin offers it.

5. Clear Google's warnings

  1. In Google Search Console, open Security & Manual Actions → Security issues.
  2. If Google lists problems, fix every one on every page, then click Request Review and describe what you did. Google says a review can take from a few days to a few weeks.
  3. Spam pages the attacker added may stay in Google's results for a while. Once they return a 404, they drop out.

Google's guide: Security issues report.

Make it harder next time

  • Keep everything updated. Most attacks use holes that already have a fix.
  • Keep regular backups stored away from the site, and check you can restore one.
  • Use a password manager and a different password for every account.
  • Remove accounts as soon as someone leaves.

If your site runs on Dirigible

The Dirigible theme already does several of these for you:

  • The theme and every Dirigible plugin update themselves, and the theme checks Dirigible Studio's signature on each update before it installs.
  • Anyone who can edit content or run the shop must choose a strong password when they set one.
  • Login and password-reset messages don't reveal which usernames exist, and usernames are hidden from the public.
  • Authors and Contributors can't paste raw iframes or style tags into pages.

See User Roles and Security. Other plugins on the site still need updating.

If the hack keeps coming back, involves customer or payment data, or you have no clean backup, bring in a professional to clean and harden the site rather than restoring it again yourself.