Skip to main content
InterProWebHost InterProWebHost
Site Security

How to Recover a Hacked WordPress Site

Strange new admin users, spammy links appearing in your pages, Google warning visitors away from your site, or emails you never sent going out from your domain: these are the classic signs of a hacked WordPress site. It feels awful, but it is recoverable, and thousands of site owners have been through exactly this. Work this plan in order. Do not skip the containment steps, and do not just clean the visible symptoms and call it done.

Step 1: Stay calm and contain it

First, do not delete everything in a panic. Change every password connected to the site right now: your WordPress admin password, your cPanel password, your client area password, and the passwords of any other admin users. If attackers still have a working login, anything you clean can be undone in minutes. Check the WordPress users list for admin accounts you do not recognize and remove them. If your site sends mail, check that attackers have not set up forwarding or new mailboxes.

Step 2: Identify how they got in

Most WordPress hacks come through a short list of doors: an outdated plugin or theme with a known vulnerability, a weak or reused admin password, or a compromised computer of someone with admin access. Check your plugins and themes for anything badly out of date. Ask everyone with admin access whether their password was weak or used elsewhere. Knowing the entry point matters because cleaning without closing it just invites a repeat visit.

Step 3: Restore from a clean backup

The fastest reliable recovery is restoring a backup from before the hack. See How Website Backups Work, and How to Restore One for the process. Pick a backup date from clearly before the first sign of trouble. If you are not sure when the hack started, go further back rather than risk restoring an already infected copy. After restoring, immediately update WordPress, all themes, and all plugins to their latest versions before doing anything else.

Step 4: If no clean backup exists, clean manually

Without a usable backup, the site must be cleaned file by file. This means replacing all WordPress core files with fresh copies, reinstalling every plugin and theme from clean sources, and carefully checking uploads folders and custom files for malicious code. This is painstaking work and easy to get wrong; missed backdoors are the reason cleaned sites get hacked again. Unless you are experienced with this, open a support ticket at this point and ask for help rather than attempting it alone.

Step 5: Close the hole for good

Recovery is not finished when the spam is gone. Work through WordPress Security Checklist: 12 Essentials and apply every item: updates on a schedule, strong unique passwords with two-factor authentication, removal of unused plugins and themes, and regular backups you actually keep. Attackers keep lists of vulnerable sites and retry them. A site that was hacked once and properly hardened is a worse target than one that was merely cleaned.

Step 6: Check the wider damage

A hack can reach beyond your pages. Check Google Search Console for security warnings on your site and request a review once you are clean, so the warnings get lifted. Check whether your domain or sending IP ended up on email blacklists, since hacked sites are often used to send spam; see Why Your Business Email Goes to Spam. If customer data may have been exposed, take that seriously and get proper advice on your notification obligations. Do not hide a data exposure; handle it properly.

Still stuck? Open a support ticket with your domain, what you are seeing, and when it started. Tell us whether you have a backup from before the hack. We will help you plan the recovery.

Continue exploring