HomeWordPress malware and hacks
WordPress malware and hacks
WordPress malware can alter pages, redirect visitors, create spam content or give an attacker continued access to your website. This library explains common WordPress hacks, the signs to look for and the steps to take when something is wrong.
Check your site now
Our free scanner looks for common signs of hacking and vulnerable plugins from outside your site.
Newly reported WordPress threats
Written within hours of the original research being published.
- WordPress XSS admin backdoor: what to do
Reported by Patchstack, 6 Oct 2026
- Japanese text in your Google results
- Thousands of new pages in Search Console
- Unknown sitemap or verified owner in Search Console
- Viagra or pharmacy words in Google results
- Spam shown to Google but not to you
- Hidden links in the page source
- Visitors sent to spam, scam or adult sites
- Redirects only on mobile or from Google
- Unknown code in .htaccess or wp_options
- Pop-up telling visitors to update Chrome or Firefox
- Download of an unknown file
- Injected script in page headers
- Casino, betting or loan pages under your domain
- Strange URLs indexed in Google
- Spam posts or pages you did not create
- Reinfection after cleaning
- Unknown PHP files in uploads or wp-includes
- Unexplained admin users or file changes
- Admin users you do not recognise
- Users that reappear after deletion
- Changed email address on your account
- Customers report card fraud after buying
- Extra fields or scripts on checkout
- Unknown scripts loading on checkout pages
- Red full-page warning in Chrome
- Security Issues report in Search Console
- Traffic drops sharply
How to tell if your WordPress site has been hacked
A compromised WordPress site does not always look obviously broken. Some attacks are designed to remain hidden from the site owner while showing spam, redirects or malicious content to search engines and selected visitors.
Warning signs include unfamiliar pages appearing in Google, unexpected administrator accounts, unexplained changes to plugins or themes, browser security warnings, visitors being redirected elsewhere, unusual JavaScript in page source, changed files and sudden additions to the database. Your hosting company may also suspend the site or report malicious files.
Google recommends checking the Security Issues report in Search Console and periodically using a Google site: search to identify pages you do not recognise. Search Console's Pages report can also expose large numbers of URLs that should not exist.
Do not assume that deleting one suspicious file has solved the problem. WordPress compromises can involve several components, including modified PHP files, malicious database entries, hidden administrator accounts, scheduled tasks or backdoors intended to restore the infection after visible malware is removed.
If you are investigating a suspected compromise, our website security information explains some of the wider controls used to protect websites.
What to do in the first hour after a WordPress hack
Avoid immediately deleting files or reinstalling WordPress. Evidence that helps identify the entry point can disappear, and a rushed restore can overwrite the only useful copy of the compromised site.
- Take a full backup first. Preserve both the website files and database and keep a separate copy of the infected site for investigation.
- Contact the hosting provider. Ask whether it has detected malicious activity, account access, unusual processes or other affected sites on the same hosting account.
- Secure every credential. Change passwords for WordPress users, hosting, the database and FTP or SFTP accounts. Replace the WordPress security salts in wp-config.php and revoke access that is no longer required.
- Check Google Search Console. Review Security Issues, Pages, messages and ownership. Investigate any unfamiliar verified owner rather than simply concentrating on the visible website.
- Record what you find. Note affected URLs, files, dates, warnings and redirects before cleanup begins.
If visitors are being put at risk, your host may be able to restrict public access while the investigation takes place.
How WordPress malware cleanup works
Effective WordPress malware removal is more than scanning for a recognisable malicious filename. The site needs to be compared with known clean software, suspicious files and database content investigated, unauthorised users removed and compromised code replaced or cleaned.
The important part is identifying how the attacker gained access. That may involve a vulnerable or abandoned plugin, an exposed account, stolen credentials, insecure hosting configuration or another site sharing the same hosting environment. Cleaning the payload without closing the entry point leaves the site open to reinfection.
After cleanup, WordPress core, themes and plugins should be brought up to date, unnecessary software removed and access permissions reviewed. Search Console should then be checked again. Where Google has applied a security warning, follow Google's review process only after the whole site has been cleaned.
Our Hacked Site Rescue is £349 fixed price and covers malware removal, a clean restore and help clearing browser and Google warnings. For ongoing protection, care plans start from £59 a month and include weekly updates, daily off-server backups, 24/7 uptime monitoring and security scanning.
Common questions
Answers to the questions we hear most about this.
What are the most common signs that a WordPress site has been hacked?
Common signs include unknown pages in Google, unexpected redirects, browser warnings, new administrator accounts, modified files, spam links, unfamiliar scripts and security alerts from your host or Google Search Console.
Should I delete infected WordPress files immediately?
No. First take a complete copy of the files and database and preserve the infected site for evidence. Removing files before investigating can destroy useful information about what changed and how the attacker gained access.
Can restoring a backup fix a hacked WordPress website?
A known clean backup can help restore the site, but the original entry point must still be identified and closed. Otherwise the restored website may be compromised again.
What passwords should I change after a WordPress hack?
Change WordPress user passwords plus hosting, database and FTP or SFTP credentials. Replace the WordPress salts in wp-config.php and review administrator accounts and other access that may have been added or compromised.
Think your site has been hacked?
Hacked Site Rescue is a fixed £249. Call us or send the details now.