How to Recover a Hacked WordPress Site (Step by Step)
Most Viral Tool - SEO Audit Tool | Reseller Profit Tracker Generator | Freelance Invoice Generator | ADHD Planner Generator
Don’t Panic — Here’s Exactly What to Do
Finding out your WordPress site has been hacked is a nightmare for any small business owner. Your site might be displaying strange content, redirecting visitors, showing warning messages in Google, or you may have completely lost access to your admin dashboard. Whatever the symptoms, quick action is critical.
The good news is that most hacked WordPress sites can be fully recovered. Follow this step-by-step guide to clean your site, restore it to working order, and lock it down so it doesn’t happen again.
Step 1: Change All Passwords Immediately
Before doing anything else, change every password connected to your site. This includes:
- WordPress admin password — log in and change it from your profile page
- Hosting cPanel or FTP password — hackers often gain server-level access
- Database password — update it in your hosting control panel
- SSH or SFTP credentials — if you use command-line access
- PHPMyAdmin or database admin passwords
Use a strong password generator — at least 16 characters with a mix of letters, numbers, and symbols. If you can’t access WordPress admin, reset the password via phpMyAdmin or your host’s control panel.
Trending Today- Earn $$$ FREE | Trending LIFE Quotes | HOT DEBATES | Autograph | FREE PAID Tools | Advertise FREE |
Step 2: Put Your Site in Maintenance Mode
You don’t want visitors seeing a hacked site or getting infected themselves. Put your site into maintenance mode while you work on recovery. You can do this through your hosting control panel, or if you still have WordPress access, use a maintenance mode plugin. If you’ve lost admin access entirely, create a static maintenance page via FTP and upload it to your public_html directory.
Step 3: Scan for Malware and Backdoors
Use a security scanning tool to identify infected files. Wordfence Security is a free plugin that performs comprehensive scans of your WordPress core files, themes, and plugins. Sucuri SiteCheck is another excellent free online scanner. Pay close attention to any files flagged as modified — hackers commonly inject malicious code into theme files, plugin files, and even core WordPress files.
Common places hackers hide backdoors include:
- Inside theme function files (functions.php)
- Recently modified plugin files
- Uploaded files in the uploads directory
- Unusual PHP files in your root WordPress directory
Step 4: Restore from a Clean Backup
If you have a recent backup from before the hack occurred, this is the fastest recovery path. Many quality WordPress hosts provide daily automatic backups. Check your hosting dashboard for backup options. Before restoring, make sure the backup predates the hack — restoring an infected backup will not solve the problem.
If you don’t have a backup, you’ll need to manually reinstall WordPress core files and then clean any infected themes and plugins. Download fresh copies from WordPress.org and your theme/plugin vendors, then upload them via FTP to replace the compromised files.
Step 5: Update Everything
Outdated software is the number one reason WordPress sites get hacked. After cleaning your site, immediately update (see our website maintenance checklist for the full routine):
- WordPress core to the latest version
- All plugins to their latest versions
- Your theme to the latest version
- PHP version on your server (ask your host if unsure)
Remove any plugins or themes you no longer use — they can be entry points even when deactivated. Check our essential WordPress plugins guide for the security plugins every small business site needs.
Step 6: Lock Down Your Site Going Forward
Prevention is always easier than recovery. Implement these security measures immediately:
- Install a security plugin — Wordfence or Sucuri for firewall protection and ongoing monitoring
- Enable two-factor authentication — adds a second layer beyond your password
- Limit login attempts — prevents brute force attacks
- Set up automated backups — daily backups stored offsite
- Use SFTP instead of FTP — encrypts file transfers
- Keep everything updated — enable automatic updates for minor WordPress releases
Step 7: Request a Security Review from Google
If Google has flagged your site with a “This site may be hacked” warning in search results, you need to clean the site first, then request a review through Google Search Console. Go to the Security & Manual Actions section and submit your reconsideration request. Once Google verifies the site is clean, the warning will be removed — though this can take a few days to a couple of weeks.
About the Author
Written by Steve | Digital Strategist at Web1Expert | 5+ years helping businesses build, optimize, and grow their online presence through web design, SEO, and content marketing.
Frequently asked questions
How do I know if my WordPress site has been hacked?
Common signs include unexpected redirects, strange admin accounts you didn’t create, modified files, Google showing a malware warning for your site, slow performance, unexpected popups, and login problems. Run a scan with Wordfence or Sucuri SiteCheck to confirm.
Can I recover a hacked WordPress site without a backup?
Yes, but it takes more work. You’ll need to reinstall WordPress core files, manually clean any infected themes and plugins, scan for backdoors, and change all passwords. The process is more time-consuming but still manageable for most site owners.
How much does it cost to fix a hacked WordPress site?
If you do it yourself, recovery is free — just your time. Professional WordPress security cleanup services typically charge between $100 and $500 depending on the severity. Sucuri offers cleanup starting at around $200.
What is the most common way WordPress sites get hacked?
Outdated plugins and themes are the most common entry point. Weak passwords, lack of two-factor authentication, and using nulled (pirated) themes or plugins also make sites vulnerable. Keeping everything updated and using strong credentials prevents the majority of attacks.

