Hacked WordPress Site? What You Need to Know

Virus Bots, skeletons and scary X's covering computer screens

Hacked WordPress site? No matter how vigilant you may be at keeping your site updated, at some point you might find yourself the unfortunate recipient of a hacked WordPress site.

If this is you, I’m sorry for your headache! Hopefully, this post will help you through it!

I’ll show you practical tips for dealing with a hacked WordPress site and what information you need to know before you hire a hack specialist.

Then we’ll cover what you need to do after your site has been cleaned.

A list of site cleaning services I’ve used in the past is provided with pros and cons of each.

You can jump to a specific topic using the links below.

  1. What Information the WordPress Hack Specialist Requires
  2. Hacked WordPress Site Repair Services
  3. What to Do After Your Hacked WordPress Site is Cleaned

Hacked WordPress Site – Now What?

This past year was exceptionally hard for WordPress site owners when several popular and well-supported plugins were compromised and removed from the WordPress.org repository until they were patched.

Since many of my clients are DIY site owners, they take responsibility for updating their plugins and themes.

The problem is if their site gets hacked, they don’t know where to turn.

And if and when they find someone ready to clean their site, they aren’t prepared with the essential information that the hack specialist will need.

This post will guide you through proactive steps you can take as well as information you will need should you find yourself the victim of a website hack.

Make Sure You Backup Your Site Routinely

Hopefully, you’ve been doing routine backups. This is critical!!

Before doing anything else, try to restore your website from a good backup. But in order to know whether or not a backup is good, you’ll need to know when your site was hacked.

If it’s been hacked for weeks, then you’ll have weekly backups of your hacked site.

Many times having a good restore point is all that you need to do ~ that is, as long as the hacker didn’t leave a backdoor on the server where he can gain re-entry to your site.

And you won’t know that until the site gets hacked again.

Just be sure that you are backing up your site on a regular basis and storing at least six months of backups but ideally a year’s worth.

So let’s get to the information you will need in order to clean your hacked site.

What Information the WordPress Hack Specialist Requires

You’ll need to provide the following information to your hack specialist so that they can access your hacked WordPress site:

WordPress Admin Access

  1. Your login URL such as https://yoursitename.com/wp-admin.
  2. Username
  3. Password

cPanel Access

You will need to provide access to your web hosting server cPanel.

  1. cPanel Login URL: https://yoursitename.com/cpanel or https://yoursitename.com:2083
    (Remember to replace yoursitename.com with your actual website domain name)
  2. Username
  3. Password

FTP Access

You may need to set up an account for this.

If you don’t know how to set up an FTP account, contact your host or follow the steps below:

  1.  Login in to cPanel
  2.  Click on FTP Accounts
Create an FTP Account

3.  The following screen will display:

Add FTP Account Screen

Fill in the information as per the screenshot and make a note of it:

a)  Log in: Log In Username (ie: support)
b)  Domain: Select the domain from the drop down
c)  Password: Select a strong password
d)  Retype the password
e)  Directory: Make sure the directory is set to public_html  or home and not a sub-directory
f)  Click Create FTP Account

If you have trouble using FTP to log into your WordPress site, please refer to this troubleshooting guide.

Once you have gathered this information, you are ready to hire a trustworthy company to do the site cleaning.

Hacked WordPress Site Repair Services

Listed below are several hack removal services I’ve personally worked with and referred clients to in the past. Each will get the job done but there are pros and cons to the services.

They all will require the information I outlined above: WordPress Login URL, cPanel access, and FTP access.

Once the site has been repaired, each service will provide you a report of what they did and steps you need to take to complete the process.

And it’s super important to make sure you follow their recommendations!

Companies that Provide Hacked WordPress Site Services


WordFence is the company behind the well-known WordFence plugin.

Their site cleaning starts at $490 for a single website.

As part of this service, WordFence will install WordFence Premium ($99) onto your WordPress site and include a one-year subscription.


I recently used them and have mixed views on recommending them.

WordFence is wildly popular and well-known to most WordPress website owners. Their free plugin has been downloaded and actively installed on over 3 million websites. So I would be remiss to leave their hack repair service off of my list.

Communication is via email and WordFence was pretty good about replying to our repeated inquiries as to the status of our cleaning.




Sucuri uses a different pricing model. As of this writing, you have three price points from which to choose:

  • Basic Plan:      12 hour response for $199.99/yr
  • Pro Plan:            6 hour response for $299.99/yr
  • Business Plan: 4 hour response for $499.99/yr


Once you sign up with Sucuri, you receive access to the Sucuri Dashboard, which is where you click on support and open a Malware Removal Request.

One nice thing about Sucuri is that if you don’t know your FTP information, as long as you can give them login information for your hosting company or cPanel access, they will take it from there.

Your yearly subscription covers unlimited malware removal requests.

The Basic Plan can be slightly lower than what you’ll pay for other services.


The Pro and Business plans are a bit more pricey than the other options, but if you can afford them and don’t want to wait, either one of them is probably your best choice. And the malware removal service is good for the entire year.



WP-Fixit claims to have same day service and that has been my experience in the past.

Their service is the most affordable at a $117 one-time cost. If you need multiple sites cleaned, you can save $20 per site.


The one thing that surprised me was that they added the WordFence and Sucuri free plugins to the site. I didn’t expect the site configuration to be altered in any way.

So keep in mind you will end up with a few more plugins on your site than you had initially.


I have found that many site owners are frustrated by the lack of communication they experience during the stressful experience of a hacked WordPress site.

Though I haven’t used this service, the company comes highly recommended by colleagues and clients. And I like the fact that you can talk to a real person throughout the process.


HackRepair.com is a US-based company that actually has a phone number and a real person to talk to.

And they advertise they actually want to talk to you! You will speak directly to the person who will be cleaning your site.


I have heard that they may install security plugins as part of the clean-up.

This may or may not be a deal-breaker for you.

What to Do After Your Hacked WordPress Site is Cleaned

There are specific steps that every reputable service will want you to take.

Please don’t ignore their recommendations and follow their protocol to ensure your site stays healthy.

Clear All Cookies and Caches

  • First off, you will want to clear your browser cache and cookies to make sure you are getting the updated, clean version of your site.
  • Then clear your site cache. If it has a local caching plugin, you can log into the WP-Admin area and click the “clear cache” button.
  • If your site is on a CDN, purge that cache, too.
  • If your host performs server-side caching, force a refresh on that.

Change All Passwords!

Test your site and if all looks well, now is the time to change all of the passwords.

Yes, it’s a tedious thing to do, but any malware clean-up is not complete until you take this very important final step.

The reason it’s so important is because if a hacker was able to get to those passwords, it puts your site back into a vulnerable position to be compromised again and again.

So here is where to find those passwords and how to change them:

Update WordPress Administrative Passwords


  1. Log into your WordPress dashboard.
  2. Go to Users>All Users.
  3. Important! Delete any admin user that should no longer have access to your site.
  4. Next change passwords for remaining admin users by hovering over the user name
  5. Click Edit
  6. Update the password
  7. Click Save

Update Hosting Control Panel (cPanel) Password


  1. Log into your cPanel account. You can do this through your customer portal or through the following link https://yoursitename.com/cpanel or https://yoursitename.com:2083
  2. In Preferences, click Password & Security.
  3. You will be prompted to add your old password and then enter a new password and confirm it. It’s best practice to choose a strong password that you aren’t using anywhere else.
cPanel Password change

Update MySQL Password


  1. Log into your cPanel account.
  2. In Databases, click MySQL Databases
  3. You will need to select the MySQL admin user that is currently associated with your WordPress database.If you are unsure of who that is, you can check your wp-config.php file in the website root directory.

 At the top of that file, you will find that info in the MySQL Settings.

In the following example, the database name is ‘mydb_dbname’.

The user is ‘mydb_myuser’.

/** The name of the database for WordPress */
define('DB_NAME', ‘mydb_dbname’);
/** MySQL database username */
define('DB_USER', 'mydb_myuser’);

  1. Go back to the MySQL screen.
  2. Scroll down to the Current Users section and click on “change password” for the user defined in the wp_config.php file:
  3. Select a new strong password and make a note of it.
  4. Change the password and save it.
  5. The wp_config.php file does NOT get updated. You need to do that manually.
  6. Open the wp_config.php file in a plain text editor. Modify the password value to match the new password and save the file.
  7. Test to make sure everything works.

Update the FTP Passwords


  1. Log into your cPanel account.
  2. Click on Files>FTP Accounts
  3. Change the FTP account password

Over to You

Hopefully this post will give you the tools and confidence you need to get your hacked WordPress site back up and running in no time.

Once you’re site is clean, you’ll want to make sure that you do everything to protect yourself moving forward.

Secure WordPress Site Set Up is critical to protecting your site from hacks and malware.

I also recommend that you get behind Cloudflare’s paid firewall. For $20/month you can rest assured that your site is being monitored 24×7 and protected from the latest threats.

And Cloudflare’s firewall will protect against plugins gone bad that could put your site at risk.

So if you aren’t on top of the latest threats and compromised plugins, Cloudflare has you covered!

I’m always on the lookout for companies providing this service and will pass along updated recommendations as they are vetted.

I would love to hear what other WordPress Site Hack cleaning services you have used.

Please add them to the comments and I’ll update my post accordingly.

Photo credit: Adobe Stock

Print Friendly, PDF & Email

About The Author

Scroll to Top