If your WordPress site is hacked, the fix is: put it in maintenance mode first, replace core files with clean copies, find and remove the injected code in your theme and plugins, rotate every password and key, then restore from a clean backup if the infection is too deep to hand-clean. Do the steps in that order. Cleaning symptoms before you've cut off attacker access just means it comes back in a few hours.
Work through the block editor and cPanel tools first. Only reach for a security plugin when you need to scan the whole file tree for injected code, which is slow and error-prone by hand.
Step 1: contain it
Before touching any files, stop the bleeding.
- Put the site in maintenance mode. This stops visitors from hitting infected pages while you work, and it stops search engines from crawling malware.
- Change your WordPress admin password immediately, along with any other admin accounts. If you don't recognize an admin user in wp-admin → Users, that's likely how the attacker got in, and it needs to be deleted, not just demoted.
- Note the symptoms. Redirects to spam sites, injected links in your footer, a defaced homepage, Google flagging the site as hacked, or a hosting suspension notice can point to different entry methods.
Step 2: take a backup of the infected state
Before you delete or overwrite anything, back up the site as it currently stands, infection included. If you make things worse mid-cleanup, you want a way back to where you started rather than nothing at all. Use the service's Backups tool (Services → your hosting → Backups) to create an on-demand backup. See Backing up your WordPress site for how the different backup layers work together.
Step 3: replace core files with clean copies
WordPress core is the easiest thing to fix, because you don't need to diff it. Download a fresh copy from wordpress.org matching your current major version, then replace every file and folder except wp-content and your existing wp-config.php. This wipes out any core file an attacker modified or planted, without touching your actual site content.
Via File Manager (portal → Services → your hosting → File Manager) or an FTP client:
- Upload the fresh WordPress zip to a temp folder.
- Extract it.
- Copy
wp-adminandwp-includesover your existing folders, overwriting everything. - Copy the loose root files (
index.php,wp-load.php, and so on) over, again overwriting. - Leave
wp-contentalone for now. That's step 4.
Do not touch wp-config.php. It holds your database credentials and unique keys, and you'll rotate those separately in step 5.
Step 4: clean themes and plugins
This is where most infections actually live, because core gets scrutinized and third-party code often doesn't.
- Delete anything you don't recognize. Open wp-admin → Plugins and wp-admin → Appearance → Themes. A plugin or theme you never installed is the infection itself, not a coincidence. Delete it, don't just deactivate it.
- Reinstall everything you keep, from source. For plugins and themes from the WordPress.org repository, delete the folder entirely and reinstall fresh from Plugins → Add New rather than trying to patch the existing files. A modified legitimate plugin is how attackers hide injected code inside something that looks normal.
- Check your active theme's
functions.phpby hand if you're running a custom or premium theme you can't just redownload cleanly. Look for anything withbase64_decode,eval,gzinflate, or a wall of obfuscated characters near the top or bottom of the file. That pattern is almost never legitimate. - Check
wp-content/uploadsfor PHP files. That folder should only ever contain images, documents, and media. Any.phpfile sitting inuploadsis a backdoor. Delete it.
If hand-checking every file feels too slow, a security scanning plugin can scan the full file tree and diff plugin/theme files against known-good repository copies, which is faster than eyeballing thousands of files. Run the scan, review what it flags, and remove or restore each match.
Step 5: rotate everything
Cleaning files doesn't help if the attacker still has valid credentials or a live session.
- Change your WordPress admin password again, now that core and plugins are clean, so a compromised session token tied to old code can't be replayed.
- Change your database password via the MySQL Databases tool (Services → your hosting → MySQL Databases in the portal), then update the new password in
wp-config.php. - Regenerate your WordPress security keys and salts in
wp-config.php. WordPress.org has a free key generator; paste the new block in to invalidate every existing login cookie at once. - Rotate your FTP account password (FTP Accounts, from Services → your hosting) and your cPanel account password via Change password on the service page, if you have any doubt about how the attacker got in, since a leaked FTP credential is a common entry point that has nothing to do with WordPress itself.
Step 6: when to restore from backup instead
Hand-cleaning works when the infection is contained to a plugin or theme. It stops being worth it when you find the same malicious code reappearing after cleanup, when you can't identify every modified file, or when the site was compromised long enough ago that you're not sure what "clean" even looked like. In those cases, restoring a full backup from before the infection date is faster and safer than continuing to chase it file by file. Use the service's Backups tool to restore single files, the whole account, or just the database, whichever matches how targeted you need the rollback to be. After restoring, still rotate every password in step 5, since the backup only fixes files, not credentials that may have leaked separately.
Once you're clean, test changes on a copy of the site before they go live again. Setting up WordPress staging gives you a safe place to update plugins and core without risking a repeat incident on the live site.
Step 7: check for lingering warnings
After cleanup, open wp-admin → Tools → Site Health. Some warnings that appear after a hack are worth acting on directly; others are already covered by your hosting stack. See WordPress Site Health warnings and which ones matter for which is which before you spend time chasing a false alarm.
When to contact support
If you can't pin down how the attacker got in, if the same infection keeps returning after cleanup, or if the site was suspended and you're not sure why, open a ticket from the portal. It goes to a real person, not a bot, and they'll help you track down the entry point.