Get a free website with any plan

See how
WORDPRESS

Cleaning a hacked WordPress site step by step

Last updated

IN SHORT

To clean a hacked WordPress site on Flashcloud, put the site in maintenance mode, replace core files with fresh copies, remove malicious theme and plugin code, and rotate all credentials. Crucially, you must cut off attacker access and contain the breach before cleaning files, or the infection will return.

If your WordPress site is hacked, the fix is: put it in maintenance mode first, replace core files with clean copies, find and remove the injected code in your theme and plugins, rotate every password and key, then restore from a clean backup if the infection is too deep to hand-clean. Do the steps in that order. Cleaning symptoms before you've cut off attacker access just means it comes back in a few hours.

Work through the block editor and cPanel tools first. Only reach for a security plugin when you need to scan the whole file tree for injected code, which is slow and error-prone by hand.

Step 1: contain it

Before touching any files, stop the bleeding.

  • Put the site in maintenance mode. This stops visitors from hitting infected pages while you work, and it stops search engines from crawling malware.
  • Change your WordPress admin password immediately, along with any other admin accounts. If you don't recognize an admin user in wp-admin → Users, that's likely how the attacker got in, and it needs to be deleted, not just demoted.
  • Note the symptoms. Redirects to spam sites, injected links in your footer, a defaced homepage, Google flagging the site as hacked, or a hosting suspension notice can point to different entry methods.

Step 2: take a backup of the infected state

Before you delete or overwrite anything, back up the site as it currently stands, infection included. If you make things worse mid-cleanup, you want a way back to where you started rather than nothing at all. Use the service's Backups tool (Services → your hosting → Backups) to create an on-demand backup. See Backing up your WordPress site for how the different backup layers work together.

Step 3: replace core files with clean copies

WordPress core is the easiest thing to fix, because you don't need to diff it. Download a fresh copy from wordpress.org matching your current major version, then replace every file and folder except wp-content and your existing wp-config.php. This wipes out any core file an attacker modified or planted, without touching your actual site content.

Via File Manager (portal → Services → your hosting → File Manager) or an FTP client:

  1. Upload the fresh WordPress zip to a temp folder.
  2. Extract it.
  3. Copy wp-admin and wp-includes over your existing folders, overwriting everything.
  4. Copy the loose root files (index.php, wp-load.php, and so on) over, again overwriting.
  5. Leave wp-content alone for now. That's step 4.

Do not touch wp-config.php. It holds your database credentials and unique keys, and you'll rotate those separately in step 5.

Step 4: clean themes and plugins

This is where most infections actually live, because core gets scrutinized and third-party code often doesn't.

  • Delete anything you don't recognize. Open wp-admin → Plugins and wp-admin → Appearance → Themes. A plugin or theme you never installed is the infection itself, not a coincidence. Delete it, don't just deactivate it.
  • Reinstall everything you keep, from source. For plugins and themes from the WordPress.org repository, delete the folder entirely and reinstall fresh from Plugins → Add New rather than trying to patch the existing files. A modified legitimate plugin is how attackers hide injected code inside something that looks normal.
  • Check your active theme's functions.php by hand if you're running a custom or premium theme you can't just redownload cleanly. Look for anything with base64_decode, eval, gzinflate, or a wall of obfuscated characters near the top or bottom of the file. That pattern is almost never legitimate.
  • Check wp-content/uploads for PHP files. That folder should only ever contain images, documents, and media. Any .php file sitting in uploads is a backdoor. Delete it.

If hand-checking every file feels too slow, a security scanning plugin can scan the full file tree and diff plugin/theme files against known-good repository copies, which is faster than eyeballing thousands of files. Run the scan, review what it flags, and remove or restore each match.

Step 5: rotate everything

Cleaning files doesn't help if the attacker still has valid credentials or a live session.

  • Change your WordPress admin password again, now that core and plugins are clean, so a compromised session token tied to old code can't be replayed.
  • Change your database password via the MySQL Databases tool (Services → your hosting → MySQL Databases in the portal), then update the new password in wp-config.php.
  • Regenerate your WordPress security keys and salts in wp-config.php. WordPress.org has a free key generator; paste the new block in to invalidate every existing login cookie at once.
  • Rotate your FTP account password (FTP Accounts, from Services → your hosting) and your cPanel account password via Change password on the service page, if you have any doubt about how the attacker got in, since a leaked FTP credential is a common entry point that has nothing to do with WordPress itself.

Step 6: when to restore from backup instead

Hand-cleaning works when the infection is contained to a plugin or theme. It stops being worth it when you find the same malicious code reappearing after cleanup, when you can't identify every modified file, or when the site was compromised long enough ago that you're not sure what "clean" even looked like. In those cases, restoring a full backup from before the infection date is faster and safer than continuing to chase it file by file. Use the service's Backups tool to restore single files, the whole account, or just the database, whichever matches how targeted you need the rollback to be. After restoring, still rotate every password in step 5, since the backup only fixes files, not credentials that may have leaked separately.

Once you're clean, test changes on a copy of the site before they go live again. Setting up WordPress staging gives you a safe place to update plugins and core without risking a repeat incident on the live site.

Step 7: check for lingering warnings

After cleanup, open wp-admin → Tools → Site Health. Some warnings that appear after a hack are worth acting on directly; others are already covered by your hosting stack. See WordPress Site Health warnings and which ones matter for which is which before you spend time chasing a false alarm.

When to contact support

If you can't pin down how the attacker got in, if the same infection keeps returning after cleanup, or if the site was suspended and you're not sure why, open a ticket from the portal. It goes to a real person, not a bot, and they'll help you track down the entry point.

Common questions

Why does malware keep returning after I clean the files?

You likely skipped rotating your credentials or left an unauthorized admin account active. Attackers regain access through active sessions, leaked database or FTP passwords, or backdoors. Clean the files, delete unknown admin users, and rotate all passwords and security keys.

Should I delete PHP files in my uploads folder?

Yes, immediately delete any PHP files found in wp-content/uploads. That folder should only store media such as images and documents. Any PHP file sitting in uploads is an attacker backdoor.

When should I restore a backup instead of hand-cleaning?

Restore a backup when malicious code reappears after cleaning, or when you cannot identify every modified file. Use the Backups tool in the Flashcloud portal to restore to a date before the breach occurred. Rotate every password immediately after the restore completes.

What should I do if I find an unfamiliar plugin on my site?

Delete it completely instead of deactivating it. An unfamiliar plugin or theme is the infection itself, not an accident. Reinstall any legitimate plugins you keep from fresh source files.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.