Act quickly. First, change your cPanel, WordPress admin, FTP, and database passwords, then take a backup of the current state for reference.
- Update WordPress core, all themes, and all plugins to the latest versions.
- Delete any unknown plugins, themes, or admin users.
- Reinstall fresh copies of WordPress core files and your active theme.
- Scan with a security plugin like Wordfence, and check
wp-config.phpand.htaccessfor injected code.
Look in cPanel for suspicious recently-modified files. cPanel's Imunify360 can detect and clean malware automatically. If you are unsure or the infection persists, open a ticket so our team can scan the account and help you recover safely.