Fix WordPress Hacked: Quick Guide to DIY

By WebCare in July 30, 2025 – Reading time 4 minute

Dealing with a Hacked WordPress Site: A Step-by-Step Guide

Oh no! Your security scans have come back positive, and it’s confirmed: your website has been successfully infiltrated.

Don’t panic! I’ve been in your shoes, and I’m here to walk you through the process of how to clean a hacked WordPress site and what next steps you should take to recover.

wordpress care hacked

Why WordPress Sites Get Hacked

First, let’s talk about why WordPress sites are so vulnerable to hacking. With over 300 million websites using WordPress, it’s no surprise that it’s the most popular target for hackers. The sheer volume of WordPress sites out there makes it an attractive target for malicious activity.

🟢 WordPress powers 2/5 Websites in the world
🟢 59,000 Plugins (free)
🟢 500+ new WordPress websites every day

Additionally, with numerous plugins and themes available, there are multiple potential entry points for hackers to exploit.

Step 1: Stay Calm and Assess the Situation

When you discover that your site has been hacked, it’s essential to stay calm and think clearly. Take a deep breath and go through this quick list of questions to assess the situation:

Record your answers to each question and make sure that you’ve noted everything for the next step.

Step 2: Contact Your Hosting Company

Many good hosting companies have experienced staff who can help you deal with a hacked site. Get in touch with your hosting provider and follow their advice.

They may be able to tell you how the hack occurred, where the backdoor is, and how to prevent future attacks. If your website is hosted on a shared server, your hosting provider can also help you determine if the hack was caused by a vulnerability on another site on the same server.

Step 3: Hire a Professional (Optional)

If your website has been severely attacked or you’re not comfortable cleaning it up yourself, consider hiring a professional. A vulnerable website only gets worse as time goes on, so the faster you can get your issues fixed, the safer your website will be.

One excellent option is Malcare, a complete WordPress security solution that can protect your online identity, or you can hire WebCare to restore your hacked website.

What to Look for in a WordPress Security Solution

When choosing a WordPress security solution, look for the following features:

FeatureDescription
Powerful ScannerA scanner that will never slow down your website and goes beyond just signature matching to find new and complex malware
One-Click Automatic Malware RemovalA feature that surgically cleans all traces of malware permanently from the website
Intelligent Plugin-Based FirewallA firewall that protects your website from bad traffic by using the collective intelligence of its network of sites
Intuitive Site Management ModuleA module that lets you manage your themes, plugins, users, and WordPress core for better security of your website

Step 4: Restore a Previous Version

If you’ve made a habit of backing up your site, now is the time to restore a previous version. Keep in mind that this will revert your website back to the version you’re restoring from, so any changes you’ve made since then will be lost. However, this may be worth it to get a clean website back.

Step 5: Scanning and Removal of Malware

If you can’t restore a previous version or prefer to clean your site manually, you’ll need to scan for and remove malware. Use a WordPress security plugin like iThemes Security to regularly scan your website and find any backdoors or malicious code.

Make sure to keep all your plugins and themes up-to-date, as outdated files can provide an entry point for hackers.

Tips for Preventing Future Hacks

To prevent future hacks, make sure to:

  • Keep all plugins and themes up-to-date
  • Use strong, unique passwords and secret keys
  • Limit user permissions and monitor user activity
  • Regularly back up your website
  • Install a WordPress security plugin and regularly scan for malware

Step 6: Check User Permissions

Check the user permissions of all your WordPress users to ensure that only authorized users have access to admin accounts. Remove any suspicious new users and make sure that user permissions haven’t been tampered with.

Step 7: Change Passwords and Secret Keys

Change all passwords related to your WordPress site, including the password to access your WP dashboard, cPanel, MySQL database, FTP, and any others that could help someone access your website. Use a password generator to ensure your password is strong, unique, and not easy for a hacker to guess. Also, change your secret keys and salts to ensure that your WordPress website is safe and secure.

Conclusion

Cleaning a hacked WordPress site can be a daunting task, but by following these steps, you can get your site back to normal. Remember to stay calm, assess the situation, and take the necessary steps to prevent future hacks.

Don’t be afraid to seek help from a professional if you’re not comfortable cleaning your site yourself. And always keep in mind that WordPress security is an ongoing effort – stay vigilant and keep your site safe!

You Made It to the End!🔥
Free Tips in Your Inbox
Get the latest, evergreen tips to secure, quicken and improve your WordPress in our weekly newsletter.
No spam policy, pure value tips/ tricks
Subscription Form

Written by

Edwin Masripan is the Lead Developer at WebCare with nearly 20 years experience in WordPress web development. He was a speaker at WordCamp (WordPress gathering).
https://webcare.co