πŸ”΅
WordPress

WordPress hacked? Step-by-step recovery

πŸ“… 8 October 2026 ✏️ 8 October 2026 ⏱ 5 min leestijd

WordPress hacked? Follow this step-by-step plan to remove malware, restore your site, and secure it again against future attacks.

A hacked WordPress site is annoying, but in most cases fully recoverable. It’s important to work methodically: first determine what happened, isolate the site, remove the malware, and only then put everything back online securely. This article guides you through every step, from the first signs to a structurally more secure installation.

HackedIsolateClean upSecured

Recognize the signs of a hack

Before you take action, it’s important to be certain that your site has actually been hacked. Typical signs include:

  • Strange content, links, or ads on your homepage or other pages
  • Unexpected redirects to other websites
  • Error messages that you did not cause yourself
  • WordPress sending spam emails without you setting this up
  • Unknown user accounts in WordPress or in your hosting environment
  • Noticeably high resource usage without a clear cause

Also check whether Google Search Console has sent a notification about malware or suspicious content; Google often automatically flags hacked sites in search results.

πŸ’‘ Tip: Review your hosting log files for suspicious IP addresses and login times. This often helps you discover the route through which the hack occurred, for example an outdated plugin or a weak password.

Create a backup and isolate the site

Once you’re certain your site has been hacked, you need to act quickly to limit further damage.

1

First make a full backup

Even of a hacked site, you want a backup so you can later compare which files have been altered. Store this separately, not on the same server.

2

Take the site offline temporarily

Place a maintenance page or disable the site. This prevents visitors from seeing harmful content and stops further spread of malware.

3

Change all passwords

Immediately change your FTP, hosting, WordPress admin, and database passwords. This blocks further unauthorized access while you clean up.

4

Check email accounts

If your business email is linked to the same domain, also check whether unauthorized access has occurred there.

Remove malware and clean up files

Now the actual recovery work begins. You can approach this in two ways, preferably combined.

With a security plugin:

  • Install a reputable plugin such as Wordfence, Sucuri, or iThemes Security
  • Run a full malware scan and remove all detected threats
  • Specifically check wp-config.php and .htaccess, as these are popular places to hide malicious code

Manual checking:

  • Search the /wp-content/uploads/ folder for files that don’t belong there, such as .php files
  • Check /wp-admin/ and /wp-includes/ for unknown or recently modified files
  • Remove unknown user accounts directly from the database
  • Check the wp_options table for suspicious values, especially around webhooks and API keys

Where possible, compare the current files with a clean, earlier backup to quickly see what has been added or modified.

Restore and secure WordPress

Once the site is clean, it’s time to renew everything and secure it structurally.

  • Update WordPress itself to the latest version
  • Update all plugins and remove plugins you no longer use
  • Replace themes with a clean version, preferably only from trusted sources
  • Enable automatic updates where possible, so known vulnerabilities are patched quickly

For extra protection against recurrence:

  • Turn on a Web Application Firewall if your hosting environment supports it
  • Enable two-factor authentication for all WordPress accounts
  • Restrict access to XML-RPC to make brute-force attacks more difficult
  • Check file permissions: 644 for files and 755 for folders is a good standard

In Plesk, you’ll find the settings for automatic updates under Websites and Domains, and under Backup Manager you can easily schedule periodic backups. If you’re considering switching to a hosting provider with daily backups and free SSL included as standard, read our explanation about switching to Tandata. The security of your business email also deserves extra attention after a hack, as attackers often try to misuse email accounts for spam.

Frequently Asked Questions

How long does it take to recover a hacked WordPress site?

This depends heavily on the scale of the hack and how many files have been affected. A limited infection can often be resolved within a few hours, while a thorough hack can take a day or longer.

Can I restore an old backup instead of cleaning up?

Only if you’re certain that backup dates from before the hack. If you restore an infected backup, you’re effectively restoring the same vulnerability.

How do I prevent my site from being hacked again?

Update WordPress, plugins, and themes regularly, use strong unique passwords, enable two-factor authentication, and scan for malware periodically.

Should I also check my domain or hosting account?

Yes. Check that no unknown subdomains or DNS changes have been added. You can read more about this in our information on domain names.

Can I get help if I can’t manage it myself?

Consult the knowledge base for more explanation, or contact your hosting provider for support in cleaning up your site.

Conclusion

A hacked WordPress site can be fixed by first confirming the hack, isolating the site, thoroughly removing malware, and then updating everything and adding extra security. A reliable hosting environment with daily backups makes this process a lot less stressful.

View web hosting β†’

Was dit artikel nuttig?