If your WordPress site is compromised, follow this professional recovery path:
- Backup: Take a full backup of the current (infected) site for analysis.
- Scan: Use tools like Fix Hacked Website SOS or server-side scanners .
- Core Files: Reinstall WordPress core files via cPanel or FTP (excluding the
wp-contentfolder). - Clean Plugins/Themes: Delete and reinstall all plugins and themes from official sources.
- Database: Search for suspicious admin users or scripts in the database.
- Passwords: Change all passwords (Hosting, FTP, WordPress Admin, and Database) .