Close Menu
WP USTAADWP USTAAD
  • About Us
  • Contact Us
  • WordPress Website
  • WordPress Themes
  • WordPress Security
  • WordPress Plugins
What's Hot

How to Fix WordPress 500 Internal Server Error & White Screen of Death (WSOD)

September 13, 2026

How to Move WordPress from Localhost to Live Server Without Losing SEO (Zero Downtime Guide)

September 13, 2026

How to Clean a Hacked WordPress Website & Remove Malware (Complete Step-by-Step Guide)

September 13, 2026
Facebook Instagram YouTube
  • Privacy Policy
  • Terms & Conditions
  • Contact Us
Facebook Instagram YouTube LinkedIn
WP USTAADWP USTAAD
  • About Us
  • Contact Us
  • WordPress Website
  • WordPress Themes
  • WordPress Security
  • WordPress Plugins
WP USTAADWP USTAAD
Home » Blog » How to Clean a Hacked WordPress Website & Remove Malware (Complete Step-by-Step Guide)
Wordpress Security

How to Clean a Hacked WordPress Website & Remove Malware (Complete Step-by-Step Guide)

Shariq MoizBy Shariq MoizSeptember 13, 2026Updated:September 13, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
How to recover your wordpress hacked website 2025
Share
Facebook Twitter LinkedIn Pinterest Email

Discovering that your WordPress website has been hacked is every webmaster’s worst nightmare. You might notice Google displaying a red security warning (“This site may be hacked” or “Deceptive site ahead”), your homepage redirecting visitors to scam websites, unauthorized admin users appearing in your database, or obscure Japanese characters dominating your Google search results (the Japanese Keyword Hack).

Hackers exploit vulnerable themes, outdated plugins, and weak passwords to inject backdoors, PHP web shells, and cryptocurrency miners. Left untreated, your domain will be blacklisted by Google, your hosting account suspended, and your organic SEO destroyed. In this emergency guide, we explain exactly how to clean a hacked WordPress site, eliminate malicious code, and secure your server in 2026.

Step 1: Immediate Triage & Containment

Do not panic, and do not immediately delete your entire server without taking a forensic snapshot. Follow this containment protocol:

  1. Put the Site in Maintenance Mode: Prevent regular visitors and Google search bots from seeing malware redirects while you work.
  2. Take an Emergency Backup: Export your database and zip your wp-content/uploads/ folder. Even if contaminated, having a copy prevents total data loss.
  3. Reset All Credentials: Change your hosting cPanel password, FTP/SSH passwords, MySQL database user password, and all WordPress administrator passwords immediately.

Step 2: Replace Core WordPress Files with Clean Copies

Malware often modifies core WordPress files like index.php, wp-settings.php, and files within wp-includes. The fastest and safest way to clean core files is to completely replace them with a fresh download from WordPress.org:

  1. Download a fresh zip of the latest WordPress version from wordpress.org.
  2. Connect to your server via SFTP or cPanel File Manager.
  3. Delete the wp-admin and wp-includes directories entirely. (Never delete wp-content or wp-config.php!).
  4. Upload the fresh wp-admin and wp-includes directories from the official zip.
  5. Replace root core files (such as index.php, wp-blog-header.php, wp-load.php) with the official fresh files.

Step 3: Hunt and Destroy Backdoors in wp-content/uploads/

The wp-content/uploads/ folder should contain only media assets (images, videos, PDFs). Hackers frequently hide PHP backdoors disguise as innocent filenames like logo.jpg.php, thumb_cache.php, or radio.php.

Run this command in your server terminal or SSH to instantly find any executable PHP scripts lurking inside your uploads directory:

find wp-content/uploads/ -type f -name "*.php"

If this command returns any files, examine and delete them immediately. Next, prevent PHP files from ever executing inside your uploads directory by adding this code into a new .htaccess file placed inside wp-content/uploads/:

<Files *.php>
deny from all
</Files>

Step 4: Scan and Clean Database Infections

Malware scripts often inject malicious JavaScript redirects into your database tables. Open phpMyAdmin and check the following:

  • Check the wp_users table: Inspect all user rows. If you see unknown accounts with administrator privileges (especially with random strings or foreign email domains), delete them immediately.
  • Search the wp_options table: Search for strings like <script, eval(, or base64_decode inside the siteurl, home, and active widget option values.
  • Inspect Scheduled Cron Jobs: Hackers use WordPress Cron (wp_cron) to re-download deleted malware files every 12 hours. Install the WP Crontrol plugin to inspect and remove suspicious background cron events.

Step 5: Reset WordPress Security Keys & Salts

If hackers stole administrative browser cookies, they can stay logged in even after you change passwords. To force-logout every single user across all devices globally, generate fresh security salts.

Visit the official salt generator: https://api.wordpress.org/secret-key/1.1/salt/. Copy the generated keys, open your wp-config.php file, and replace the existing 8 lines of AUTH_KEY and SECURE_AUTH_KEY definitions.

Step 6: Request Google Search Console Security Review

Once your site is 100% clean and verified with a security plugin like Wordfence or MalCare:

  1. Log in to Google Search Console.
  2. Navigate to Security & Manual Actions > Security Issues.
  3. Click “Request Review”.
  4. Provide a concise technical summary explaining that core files were replaced, malicious scripts deleted, vulnerabilities patched, and credentials changed. Google typically removes red warning flags within 24 to 72 hours.

For more proactive protection strategies, read our guide on Automated Backups & Disaster Recovery and learn how to configure an edge web application firewall in our Cloudflare WordPress Security Guide.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBest WordPress Hosting in Pakistan (2026 Review): Speed, Price, Local Payment & Latency
Next Article How to Move WordPress from Localhost to Live Server Without Losing SEO (Zero Downtime Guide)
Shariq Moiz
  • Website

Shariq Moiz is a Full-Stack WordPress Engineer, Performance Architect, and Founder of WP Ustaad based in North Nazimabad, Karachi, Pakistan. Specializing in Core Web Vitals, speed optimization, theme development, and high-scale WooCommerce systems.

Related Posts

Wordpress Security

How to Set Up Cloudflare with WordPress in 2026 (Free SSL, Edge Caching & Security WAF)

September 13, 2026
Wordpress Security

How to Restore a Hacked WordPress Website in 2025

July 27, 2025
Wordpress Security

WordPress Security in 2025: Protect Your Site with This Step-by-Step Guide

July 26, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Top 10 Contact Form Plugins for WordPress in 2026 (Speed & Features Tested)

September 8, 2018

The Fastest WordPress Themes in 2026: Speed Benchmark & Core Web Vitals Comparison

September 8, 2018

WordPress Security in 2025: Protect Your Site with This Step-by-Step Guide

July 26, 2025
⚡ WP USTAAD
Learn  |  Build  |  Grow

WP Ustaad is a premier educational hub offering battle-tested WordPress tutorials, theme reviews, speed optimization tips, and security guides based in North Nazimabad, Karachi.

📖 Expert Guides 🛡️ Practical Tips ⚡ For All Levels

CONNECT WITH US

QUICK LINKS

  • › Home
  • › About Us
  • › Privacy Policy
  • › Disclaimer
  • › Contact Us
  • › Terms & Conditions
  • › Free Resources
  • › All Tutorials

🔥 MOST POPULAR

Top 20 Must-Have WordPress Plugins July 26, 2025
How to Use AI in WordPress (Fast Guide) July 27, 2025
WordPress Security
WordPress Security in 2025: Protect Your Site July 26, 2025
WordPress Plugins
Best WordPress Plugins for Beginners July 26, 2025

⭐ OUR PICKS

Avada Theme
Best WordPress Theme: Why Developers Choose Avada July 27, 2025
Create WordPress Website
How to Create a WordPress Website (Beginner's Guide) July 27, 2025
Migrate WordPress
How to Migrate Your WordPress Website (2025 Guide) July 27, 2025
© 2026 WP USTAAD

Type above and press Enter to search. Press Esc to cancel.