WordPress Site Hacked? What to Do, in the Right Order
WordPress site hacked? How to fix it in the right order: contain, preserve, clean or restore, close the gap, clear Google, plus your POPIA duty if data leaked.
Your site is showing someone else's content, redirecting visitors to spam, or Google is warning people away from it. If you are searching WordPress site hacked how to fix, the order matters more than the tools: contain the damage, preserve a copy, clean the site or restore from a backup that predates the break-in, close the way they got in, then ask Google to clear the warning. Do it out of order and the hack usually comes back.
Below is that order, plus the two things foreign guides leave out: working with a South African host, and your POPIA duty if customer data was exposed.
First, contain the damage before you delete anything
- Take the site offline. Put it in maintenance mode or ask your host to block public traffic, so it stops serving malware to visitors while you work [2].
- Change passwords from a computer you know is clean. Attackers sometimes plant software on an owner's laptop to read logins as they are typed [2].
- Change every access point, not just your WordPress password: SFTP or FTP, the WordPress admin, cPanel and the database, for all users [4]. Resetting WordPress's secret keys logs out any hijacked sessions [4].
- Call your host. On most South African shared hosting, support can confirm the compromise, check server logs and tell you which backups they hold.
- Save a copy of the infected site and database before cleaning. It shows what happened and when, and helps if you need to report the breach.
That last step is the same discipline I use on every deploy to a South African cPanel host: a timestamped copy of the build and a database dump before anything changes. I describe it in Git deployment on cPanel shared hosting.
How do you know it is actually hacked?
Not every broken site is hacked. A plugin update that conflicts with your theme can also break pages. Common signs of a real compromise:
- Visitors are redirected to another site, often only on mobile or only when arriving from Google.
- New admin users you did not create, or you are locked out of your own admin.
- Spam pages appearing in Google results for your domain.
- Your host or Google reporting malware, or your emails suddenly landing in spam.
Redirects often live in the .htaccess file, a server configuration file that WordPress.org calls one of the more common targets for malicious changes [4]. If you cannot log in, WordPress.org's password reset guide covers resetting the password through phpMyAdmin, the database tool most cPanel hosts provide [8].
Clean it or restore a backup: what actually fixes a hacked WordPress site
Restoring a backup is the fastest fix, with two conditions. The backup must predate the break-in, because a backup taken after it carries the backdoor along with it [2]. And you must still close the entry point: restoring alone is not enough, and if the vulnerability is not fixed, attackers can simply hack the site again [3]. Ask your host exactly which restore points it still holds and how far back they go, because retention varies between hosts and plans. That uncertainty is why saving the infected copy first matters.
If there is no clean backup, the safer default is to rebuild from clean sources rather than hunt for every bad file:
- After saving your evidence copy, replace the WordPress core directories with clean copies of the same version, rather than using the reinstall button in the admin, because installers often only overwrite existing files and hacks often add new ones [4]. Uploading over the top can leave extra malicious files behind, so replace, do not merge.
- Inspect your uploads folder and your database too, because both can hold injected code that a core reinstall does not touch.
- Reinstall each plugin and theme from its official source, and delete any you do not use.
- Keep only your uploads and content, and check the uploads folder for files that should not be there.
Scanners help, but a remote scan cannot see everything on the server, and backdoors can survive it [5]. In my experience, two habits make recovery much easier: keeping known-good snapshots you can restore from, and keeping admin and API credentials out of files on the server. Neither prevents a hack, but both limit what an attacker gets and how long you are down.
If customer data was exposed: your POPIA duty
This is the step most foreign guides miss. Section 22 of POPIA says that where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator, and must also notify the affected people unless their identity cannot be established [6]. That identity exception applies only to notifying the people, not to notifying the Regulator.
The Act says notification must be made as soon as reasonably possible after the compromise is discovered, and notice to the people affected may only be delayed if a public body or the Regulator determines it would impede a criminal investigation [6]. The Information Regulator says security compromise notifications must now be reported through its eServices Portal [7].
If your site holds customer accounts, orders or enquiries, assess urgently, with qualified legal advice, whether the section 22 trigger has been met. I cover the wider obligations in POPIA and your website. If your store holds payment gateway keys, change those too.
Clear the Google warning and get back online
Only once the site is clean, request a review in Google Search Console. A review requested while malicious files are still on the server fails, and you start the wait again [2]. Elementor puts the typical time for Google to recrawl and remove the warning at 24 to 72 hours [3]. Check the site afterwards in a private browser window and on mobile data, because some hacks only show to logged-out visitors.
Why WordPress sites keep getting hacked
Attackers rarely pick you specifically: they use automated bots to scan huge numbers of websites for common weaknesses [3]. The usual entry points are outdated plugins, themes or core, which Elementor calls the most common cause [3]; "free" copies of premium plugins, which very often carry malware [3]; weak passwords; and cheap shared servers, where one infected site can spread to others on the same server [3].
“A hack that comes back was never fixed. Something is still open.”
WPBeginner also notes that attackers increasingly use AI to exploit newly patched plugin vulnerabilities [1], which shortens the safe gap between an update being released and being needed. Prevention is risk reduction, not a guarantee: prompt updates, two-factor login, no nulled plugins, a firewall, and backups you have actually tested. I explain what that looks like week to week in what website maintenance includes, and the e-commerce side in is WordPress safe for e-commerce.
What to do next
- If you are mid-incident, take the site offline and call your host now.
- Save a copy of the infected files and database before changing anything.
- If customer data could have been accessed, get qualified legal advice quickly on whether section 22 notification is required.
- Clean or restore from a pre-hack backup, then close the entry point and change every password.
- Get professional help if you are locked out, the hack keeps returning, or a live store is involved.
If your site has been hacked and you are not sure where to start, get in touch and I will help you work through it in the right order.
Sources
- Beginner's Guide to Fixing Your Hacked WordPress Site, WPBeginner, 9 September 2026
- What to Do If Your WordPress Site Is Hacked, Codeable, 24 September 2026
- WordPress Hacked? A Complete Guide to Restoring and Securing Your Site, Elementor, 29 June 2026
- FAQ My site was hacked, WordPress.org, 26 July 2026
- How to Remove Malware and Clean a Hacked WordPress Site, Sucuri, 4 October 2026
- Protection of Personal Information Act 4 of 2013, Government of South Africa, 4 October 2026
- Protection of Personal Information, Information Regulator, 4 October 2026
- Reset your password, WordPress.org, 27 March 2026