If your WordPress site was hacked, work in this order: contain it, back it up, change every password, clean out the malware, close the hole the attackers used, then ask Google to review your site. Skip the root cause, and attackers can walk right back in.
Below is the full 9-step plan for a hacked WordPress site, based on the recovery guides from Google and WordPress.org, plus what it costs and how to keep it from happening again.
Signs Your WordPress Site Has Been Hacked
- Google shows a warning about your site in search results, or Chrome shows a red warning page before your site loads.
- Search Console emails you about a security issue.
- You find admin users, plugins, or files you didn’t add.
- A Google search for site:yourdomain.com shows spam pages you didn’t create, often in another language or selling pills.
- Visitors get sent to other websites, sometimes only on phones or only when they click through from Google.
- Your host suspends your account or warns you about malware.
- Customers say they’re getting spam from your domain.
One warning that isn’t a hack: an expired SSL certificate. It also puts a full-page warning in front of visitors. Here’s how the new 200-day SSL certificate limit works.
Why WordPress Sites Get Hacked
Most attacks don’t target WordPress itself. They target add-ons. Patchstack found 11,334 new vulnerabilities in the WordPress ecosystem in 2025, up 42% from 2024. 91% were in plugins and 9% were in themes. Just six were in WordPress core.
Attackers move fast, too. Patchstack reports that for the most heavily exploited flaws, the median time to mass exploitation was five hours. And 46% of the vulnerabilities had no patch when they were disclosed. That’s why updates alone aren’t enough. You also need a firewall, backups, and monitoring.
What to Do If Your WordPress Site Is Hacked: 9 Steps
1. Contain the damage and call your host
Put the site in maintenance mode or take it offline, so visitors don’t get infected or redirected. Then contact your hosting company. Your host may see the attack in its logs and can often help. Google’s guide for hacked sites starts with these same two moves.
2. Back up the hacked site before you change anything
Copy all of your files and the database as they are right now. It feels backward, but it gives you a record of the attack and a way back if a cleanup step breaks something.
3. Scan your own computer
An infection can start on the computer you use to log in. The WordPress.org hacked-site FAQ says to scan it first, so you don’t hand your new passwords to malware.
4. Change every password and remove unknown users
Reset passwords for every WordPress admin, your hosting account, SFTP, the database, and the email tied to the site. Reset the WordPress security keys to log everyone out. Delete admin users you don’t recognize, and turn on two-factor login.
5. Check Google Search Console
Open the Security Issues report to see what Google found and on which pages. You can also look up your domain in Google’s Safe Browsing site status tool. Our guide to what a real SEO audit checks shows how Search Console fits into regular monitoring.
6. Clean the site
If you have a clean backup from before the hack, restoring it is often the fastest fix. If you don’t, reinstall the WordPress core files (the wp-admin and wp-includes folders). Then reinstall plugins and themes from their official sources. Check .htaccess, wp-config.php, your theme files, and the uploads folder for code you didn’t add. Remove any plugin or theme you can’t verify.
7. Find and close the hole
Cleaning without fixing the cause invites a repeat. Update WordPress, every plugin, and every theme. Delete the ones you don’t use. If a plugin has a known flaw with no fix yet, replace it, or put a web application firewall in front of the site.
8. Ask Google to review your site
Once the site is clean, request a review in the Security Issues report. Google says reviews take from a few days to a few weeks, and it emails you as they move along. Don’t request one early. A review requested before every issue is fixed can slow the next one or get your site marked as a repeat offender.
9. Harden the site and keep watching
Turn on automatic updates for plugins and themes, a WordPress feature since version 5.5. Keep daily backups somewhere other than your server. Add malware scanning and a firewall. Then change your passwords one more time after the cleanup, as WordPress.org recommends.
Good hosting handles much of this for you. Compare options in our guide to the best WordPress hosting for Las Vegas small businesses.
Mistakes That Lead to a Second Hack
- Restoring a backup and calling it done. If the hole is still open, the attacker comes back.
- Deleting only the spam you can see. Backdoors hide in places you won’t notice, like the uploads folder or a fake plugin.
- Keeping the same passwords. Assume every old password is known.
- Requesting a Google review too soon. It can slow down the next review.
- Installing free copies of paid plugins. You can’t check what’s hidden inside them.
How Much Does Hacked WordPress Cleanup Cost?
Cleanup can be a one-time bill or part of a plan. Our Website Security plans include a firewall and malware scanning. Standard covers one site cleanup a year, while Advanced and Premium include unlimited cleanups. Plans start at $5.99/mo.
On our Managed WordPress hosting, daily malware scans and a web application firewall come built in. Deluxe adds one-time malware removal, and Ultimate includes unlimited malware removal.
Would you rather hand it all off? Our WordPress Website Care Plan covers updates, security monitoring, daily backups, and uptime alerts for $197 a month.
When to Call a Professional
Get help right away if your site takes payments, stores customer data, or keeps getting reinfected. If customer data may have been exposed, talk to an attorney about your notification duties. This guide is general information, not legal advice.
MCNM Marketing is based in Las Vegas. We help local businesses recover hacked WordPress sites and set up the protection that keeps them clean.
Not an emergency? Compare our website security plans and protect your site before anything happens.
Frequently Asked Questions
How do I know if my WordPress site has been hacked?
Common signs include a Google warning in search results or Chrome, a security alert in Search Console, admin users you didn’t create, spam pages in Google results for your domain, and redirects to other sites. Your host may also suspend your account after it finds malware.
Can a hacked WordPress site be fixed without losing content?
In most cases, yes. A cleanup removes the bad code and any spam it added, reinstalls WordPress and plugins from clean copies, and keeps your real posts, pages, and images. A clean backup from before the hack makes recovery faster.
How long does it take Google to remove a hacked site warning?
After you fix the problem and request a review in Search Console, Google says reviews take from a few days to a few weeks, and it emails you as the review progresses. Requesting a review before the site is fully clean can slow things down.
Why do WordPress sites get hacked?
Mostly through plugins and themes. Patchstack found 11,334 new WordPress vulnerabilities in 2025. 91% were in plugins, 9% were in themes, and only six were in WordPress core. That’s why WordPress.org’s security guidance stresses keeping everything updated and using strong passwords.
Does a firewall stop WordPress hacks?
It lowers the risk, but it doesn’t remove it. Patchstack found that 46% of WordPress vulnerabilities disclosed in 2025 had no patch yet, and a web application firewall can help block attacks on those flaws. You still need updates, backups, and strong passwords.
Sources
- Google: Help for hacked sites, Security Issues report, and Safe Browsing site status
- WordPress.org: FAQ: My site was hacked, Hardening WordPress, and Plugin and theme auto-updates
- Patchstack: State of WordPress Security in 2026


Leave a Reply