Cloud Service >> Knowledgebase >> FTP >> Steps to Replace a Hacked WordPress Site
submit query

Cut Hosting Costs! Submit Query Today!

Steps to Replace a Hacked WordPress Site

Steps to Replace a Hacked WordPress Site

If your WordPress site has been hacked, it's crucial to act quickly to secure it and restore it to a safe state. Here’s a step-by-step guide to help you replace your hacked site.

Step 1: Identify the Hack

Check for Signs:

Unusual activity (e.g., spam posts, unknown users).

Site defacement or unexpected redirects.

Alerts from security plugins or your cloud hosting provider.

Step 2: Backup Your Current Site

Even though your site is hacked, you should back up what you can:

Files:

Use an FTP client (like FileZilla) to download all files from your WordPress root directory.

Database:

Access your hosting control panel (e.g., cPanel) and use phpMyAdmin to export your database.

Step 3: Scan for Malware

Use Security Plugins:

Install a security wordpress plugin (like Wordfence or Sucuri) to scan for malware and vulnerabilities.

Follow the plugin’s instructions to clean up the site.

Step 4: Change All Passwords

Admin Password:

Go to Users > All Users in your WordPress dashboard and update the admin password.

Database Password:

Change the database password via your hosting control panel.

FTP and Hosting Passwords:

Update passwords for your FTP account and hosting control panel.

Step 5: Replace Core Files

Download a Fresh Copy of WordPress:

Go to the WordPress.org download page and download the latest version.

Upload Fresh Files:

Extract the downloaded ZIP file.

Using FTP, upload the new wp-admin and wp-includes folders to your server, overwriting the existing ones.

Step 6: Check and Reinstall Plugins and Themes

Delete Infected Plugins/Themes:

Delete any suspicious or outdated plugins and themes.

Reinstall Trusted Plugins/Themes:

Download and install fresh copies of any plugins/themes you need from official sources.

Step 7: Restore from Backup (if available)

If you have a clean backup from before the hack:

Restore Files:

Upload the backup files via FTP.

Restore Database:

Use phpMyAdmin to import the backup database.

Step 8: Secure Your Site

Update Everything:

Ensure WordPress core, themes, and plugins are up to date.

Install Security Plugins:

Use security plugins to enhance protection (e.g., Sucuri, Wordfence).

Set Up Two-Factor Authentication:

Add an extra layer of security for admin logins.

Step 9: Monitor Your Site

Regular Scans:

Schedule regular malware scans and monitor for unusual activity.

Backups:

Set up automatic backups to ensure you can quickly recover in case of future issues.

Conclusion

Replacing a hacked WordPress website online can be tough, but through following those steps, you can restore your site to a secure state. Always prioritize security features to save you destiny hacks. If you're uncertain or the hack is excessive, don't forget consulting a professional.

Cut Hosting Costs! Submit Query Today!

Grow With Us

Let’s talk about the future, and make it happen!