Discovering your WordPress site has been hacked is a gut-punch, but the first 24 hours matter more than the panic. A hacked WordPress site is usually recoverable, and how fast you get back to normal depends almost entirely on acting in the right order. This is the calm, step-by-step version of what those first 24 hours should look like.
First, confirm and contain
Before changing anything, confirm it is actually a compromise — unexpected redirects, spam content, a warning in search results, or a host notice — and then contain it. If your host offers it, take the site into maintenance mode or temporarily restrict access so the damage stops spreading and visitors are not exposed to malicious content while you work.
Do not start deleting things at random. The goal in the first hour is to stop the bleeding and preserve evidence of how they got in, not to make it worse.
Step 1: Change every credential
Assume the attacker has access to everything. Reset passwords for WordPress admin accounts, hosting and control-panel logins, database, and FTP/SFTP. Rotate security keys (the salts in wp-config). If there are admin users you do not recognize, that is a strong sign of compromise — note them, but change credentials first so you are not locked in a loop with the attacker.
Step 2: Get a clean backup in hand
Identify the most recent backup from before the compromise. This is where a host with reliable, point-in-time backups turns a crisis into an inconvenience — you can roll back to a known-good state instead of trying to clean an infected site by hand. If you are not certain when the hack happened, a host that keeps enough history lets you find the last clean version.
Step 3: Find and remove the infection
With credentials secured, scan for malware and remove it. Common hiding spots are modified core files, malicious code injected into theme or plugin files, unfamiliar files in the uploads folder, and rogue scheduled tasks. Compare against known-good copies of WordPress core, your theme, and plugins, and replace anything altered. This is the step where professional help pays for itself — missing one backdoor means the site gets reinfected days later.
Step 4: Close the door they came in
Removing the malware is not enough if the way in is still open. Update WordPress core, all plugins, and themes to current versions, since outdated software is the most common entry point. Remove plugins and themes you do not use. Confirm file permissions are sane. The point is to make sure the same hole is not sitting there waiting to be used again.
Step 5: Restore, harden, and monitor
Bring the clean site back online, then add the protection that prevents a repeat: a firewall, malware scanning, strong authentication, and ongoing monitoring. Finally, if the hack triggered a search-engine warning, request a review once the site is clean so the warning is lifted.
How to make the next 24 hours never happen
Recovery is reactive; the real win is not needing it. Managed hosting with daily backups, active security monitoring, and a firewall turns “we got hacked” from a disaster into an event your host handles. If cleaning this up yourself sounds like a bad week, that is exactly the work a technical support plan covers.
Frequently asked questions
Can a hacked WordPress site be fully recovered?
In most cases, yes — especially with a clean pre-hack backup. The keys are acting quickly, removing every trace of the malware (including backdoors), and closing the vulnerability that let them in so it does not recur.
How did my WordPress site get hacked?
Most commonly through outdated core, plugins, or themes, weak or reused passwords, or a vulnerable plugin. Keeping everything updated and using strong authentication closes the majority of entry points.
Should I try to clean it myself or get help?
If the site drives revenue, professional help is usually worth it — the risk of a DIY cleanup is missing a hidden backdoor and getting reinfected. A managed host can handle recovery and prevention as part of the service.
Dealing with a compromised site right now? We offer same-day options — see our WordPress technical support and recovery. If you need hands on it today, our emergency WordPress support covers exactly this situation.




