My WordPress Site Has Been Hacked: How to Fix It (2026 Guide)
July 7, 2026
WordPress website security AI websites
Your website is redirecting visitors to a sketchy pharmacy site. Google slapped a "This site may be hacked" warning on your search listing. Or you just tried to log in and your admin password doesn't work anymore.
Take a breath. If your WordPress site has been hacked, it is fixable, but the next few hours matter. Here's exactly what to do, in order.
How do I know if my WordPress site has been hacked?
Sometimes the hack is obvious. Often it hides for weeks while quietly damaging your rankings and your reputation. These are the signs a WordPress site has been hacked:
- Google shows a "This site may be hacked" or "Deceptive site ahead" warning on your listing or when visitors click through
- Your site redirects to a pharmacy, casino, or other spam page you have never seen
- Strange pages or spammy links appear in Google's index for your domain (search `site:yourdomain.com` and look for anything you did not publish)
- You cannot log in, or you find admin accounts you did not create
- Your host suspends the site or emails you about malware or outbound spam
- The site is suddenly slow, throwing errors, or serving pop-ups and ads that are not yours
- A security scanner like Wordfence or Sucuri flags modified core files or known backdoors
If even one of these is true, treat it as a confirmed compromise and work through the steps below. A site that looks fine to you can still be flagged as hacked by Google, so check Google Search Console's Security Issues section either way.
Step 1: Take the site offline (the right way)
Don't start deleting files. You could destroy the evidence you need to figure out how they got in, and you might not even remove the actual backdoor.
- Put the site into maintenance mode through your hosting panel, or point visitors to a simple "we'll be right back" page
- If your host offers it, isolate the site so it can't infect anything else on the account
- Tell your team not to log in until you've finished the next step
Taking the site down protects your visitors and stops the damage from spreading to your reputation.
Step 2: Change every password, not just the WordPress one
Attackers rarely stop at your WP admin. Reset all of these, from a device you trust:
- Your hosting account password
- WordPress admin passwords (every admin, not just yours)
- FTP / SFTP credentials
- The database password (in your hosting panel, then update wp-config.php)
- Your email password, if it's tied to the hosting account
Turn on two-factor authentication anywhere it's offered. If a password was reused on other sites, change it there too.
Step 3: Call your hosting company
Most hosts have dealt with this thousands of times. Ask them:
- When the compromise likely happened (they can often see it in server logs)
- Whether other sites on your account are affected
- Whether they have a clean backup from before the hack
That last one is your best friend. A restore from a clean backup plus fresh updates is usually faster and more reliable than trying to hand-clean infected files.
Step 4: Find out what they touched
Before you restore, do a quick damage assessment:
- Check your user list. Look for admin accounts you didn't create and delete them.
- Run a malware scan. Tools like Wordfence or Sucuri's scanner will flag modified core files and known backdoors.
- Check Google Search Console. The Security Issues section tells you what Google found, and it's how you'll request a review later.
- Look at recently modified files. Backdoors love to hide in wp-content/uploads, theme files, and fake "plugin" folders.
Step 5: Clean or restore
If you have a clean backup: restore it, then immediately update WordPress core, every theme, and every plugin before the site goes public again. The same hole that let them in the first time is still there in your backup.
If you don't have a clean backup: reinstall WordPress core fresh, reinstall your theme and plugins from their original sources (never from your infected copy), and go through the database for injected spam links and rogue users. If that sounds beyond your comfort level, it's worth paying a professional cleanup service. A half-cleaned site gets re-hacked within weeks.
Step 6: Get off Google's blocklist
Once the site is verifiably clean, go to Google Search Console, open Security Issues, and Request a Review. Be honest about what happened and what you fixed. Reviews usually clear in a few days, and the warning disappears from your search results.
Why do WordPress sites get hacked?
Almost no small business gets hacked because someone targeted them personally. WordPress runs a huge share of the web, which makes the platform itself the single biggest target on the internet, and the attacks are automated. Here is why WordPress sites get hacked so often:
- Outdated plugins and themes. This is the number one cause. Every plugin is third-party code with its own security holes, and a bot scanning millions of sites a day only needs to find one you forgot to update.
- Weak or reused passwords. Automated login attempts (brute-force attacks) hammer wp-admin around the clock looking for easy credentials.
- Outdated WordPress core or PHP. The underlying software has to be patched constantly, and every skipped update leaves a known door open.
- Nulled or pirated plugins and themes. "Free" premium plugins from sketchy sites frequently ship with backdoors already installed.
- Shared or low-quality hosting. One compromised site on a cheap shared server can spread to yours.
The uncomfortable truth is that the WordPress model guarantees the treadmill never stops: a stack of third-party plugins bolted on top of a database and PHP code that all must be patched forever. Miss one update and you are back where you started. That is the root cause this guide keeps circling back to.
Step 7: Ask the harder question
Here's the part most tutorials skip: why did this happen, and will it happen again?
WordPress powers a huge share of the web, which makes it the biggest target on the internet. And the way it works guarantees the treadmill never stops: dozens of third-party plugins, each one a potential unlocked door, sit on top of a database and PHP code that must be patched constantly. Miss one plugin update and you're back where you started. Most hacked WordPress sites weren't attacked by a genius. They were attacked by a bot that scans millions of sites a day for one outdated plugin.
You can keep running on that treadmill. Or you can step off it.
There's a better way to have a website in 2026
At Oxsome, we've moved way beyond WordPress. We build AI-powered websites on a modern stack, and the difference isn't subtle:
- Dramatically more secure. No plugin stack to exploit, no database bolted to your public pages, no monthly patch roulette. The attack surface that got you hacked simply doesn't exist.
- Faster. Modern sites load in a fraction of the time of a typical plugin-heavy WordPress build, and speed directly affects your Google rankings and your conversion rate.
- More efficient. AI does the heavy lifting on content, SEO, and updates, so you're not paying a developer every time you need a change, and you're not babysitting a dashboard full of update warnings.
If you're reading this because your WordPress site just got hacked, get it cleaned up using the steps above. That part matters. But when you're ready to make sure this never happens again, talk to us. We'll show you what your site looks like rebuilt on a platform that's better, faster, and doesn't need rescuing.
Frequently asked questions
Can a hacked WordPress site be recovered?
Yes. In almost every case a hacked WordPress site can be fully recovered. The two reliable paths are restoring a clean backup from before the compromise, then updating WordPress core, themes, and plugins before it goes public again, or, if you have no clean backup, reinstalling WordPress and your plugins from their original sources and cleaning the database of injected code and rogue users. The one thing that turns a recoverable site into a lost one is deleting files in a panic before you know how the attackers got in. Work through the steps above in order, and if a full manual cleanup is beyond your comfort level, a professional cleanup service can do it for you.
How long does it take to fix a hacked WordPress site?
It depends on the scope of the damage, not on a flat number. A straightforward case with a clean backup can be restored and updated in a few hours. A site with no backup, an unknown entry point, or a deep infection across the database and file system takes longer, because every backdoor has to be found and every source of reinfection closed. Clearing Google's "site may be hacked" warning is a separate step that usually takes a few days after you request a review in Search Console. The honest answer is that finding and closing the hole takes longer than the cleanup itself.
How much does it cost to fix a hacked WordPress site?
It depends on scope rather than a fixed price. If you have a clean backup and are comfortable in your hosting panel, the direct cost can be close to nothing beyond your time. A professional malware removal and hardening service costs more, and the price scales with how deep the infection goes and whether the entry point is obvious. Judge any quote against the cost of the site staying down: lost customers, lost rankings, and lost trust while it sits behind a Google warning. A cheap cleanup that misses the backdoor is the most expensive option, because a half-cleaned site gets re-hacked within weeks.
Will my WordPress site get hacked again?
It can, and that is the real problem with the WordPress model. Cleaning the site closes today's hole, but the attack surface that let the bots in stays exactly the same: a stack of third-party plugins on top of core software that all must be patched forever. Miss one plugin update and you are exposed again. You can lower the odds with constant updates, strong passwords, two-factor authentication, and a security plugin, but you are managing risk on a treadmill, not removing it. The only way to make sure it never happens again is to remove the attack surface itself, which is why we build AI-powered websites with no plugin stack and no public-facing database to exploit.
Ready to stop rescuing your website? Talk to us and we'll show you what your site looks like rebuilt on a platform that doesn't need rescuing.