A hosting alert, strange redirects, unknown users, browser warnings or unauthorised changes can indicate a compromised WordPress website. Not every technical issue is malware, but treat the signs carefully until the cause is confirmed.
The first priority is not restoring the visual appearance. It is preserving information, containing the issue and recovering control without deleting evidence or reinstalling the same vulnerability.
1. Record what is happening
Note when the issue appeared, affected pages, hosting or browser messages and recent plugin, theme, user or access changes. Save screenshots and provider notices. This helps distinguish a service outage, a configuration problem and a genuine compromise.
2. Avoid impulsive changes
Do not delete files at random or restore a backup without assessing the cause. A restoration can temporarily return the site, but the incident may recur if the vulnerable plugin, exposed credential or compromised access remains.
If the site handles purchases, sensitive forms or customer information, ask the hosting provider whether public access should be temporarily limited during review.
3. Preserve the affected state
Before cleaning, retain a copy of the affected files and database. It can help investigate what changed or recover legitimate content missing from an earlier backup. Check which backups are available and whether they include both files and database.
4. Review access and the environment
Change passwords for WordPress, hosting, SFTP or SSH, database, administrative email and connected services. Use unique passwords and enable two-factor authentication where possible. Review the computers used to administer the site too.
5. Clean, update and identify the cause
Review modified files, users, plugins, themes, scheduled tasks and configuration. Then update WordPress, extensions and themes from legitimate sources, and remove unused components.
WordPress’s official guidance for compromised sites recommends documenting symptoms, scanning the site and environment, reviewing backups and understanding the entry point before closing the case.
If the site is blocked, customer data is involved or the problem returns after restoration, request a WordPress malware cleanup. Afterwards, establish a managed hosting routine.
