How do I clean a hacked WordPress site? Print

  • 0

Act quickly. First, change your cPanel, WordPress admin, FTP, and database passwords, then take a backup of the current state for reference.

  1. Update WordPress core, all themes, and all plugins to the latest versions.
  2. Delete any unknown plugins, themes, or admin users.
  3. Reinstall fresh copies of WordPress core files and your active theme.
  4. Scan with a security plugin like Wordfence, and check wp-config.php and .htaccess for injected code.

Look in cPanel for suspicious recently-modified files. cPanel's Imunify360 can detect and clean malware automatically. If you are unsure or the infection persists, open a ticket so our team can scan the account and help you recover safely.


Was this answer helpful?

« Back