What to do if your WordPress site has been hacked
- Immediately change passwords. Your WordPress user account and all accounts with administrative permissions on the website. MySQL password for your website database and password for MySQL server administrator. FTP, if it used.
- Reinstall WordPress. Manually remove old one and install again (don’t forget preserve uploads folder). Download latest stable release from wordpress.org.
- Reinstall all plugins and theme. Use latest stable releases. Reinstall means remove all folders and files from previous installation. Don’t copy new files over files and folders that exists.
- Change security keys in the wp-config.php file. Get it from: https://api.wordpress.org/secret-key/1.1/salt/
- Make chmod 444 for wp-config.php.
- Check uploads folder(s) for php files. Remove it without doubt.
- Put .htaccess file to the uploads folder with string in it
php_flag engine off
- Check theme with Theme Check plugin.
Last posts from WordPress security blog
- Brute-force, DoS, and DDoS attacks – what’s the difference? 04/10/2017
- WP Cerber 4.5 03/22/2017
- Instant mobile and browser notifications with Pushbullet 03/20/2017
- Best WordPress Plugins for Two-Factor Authentication 03/15/2017
- WordPress 4.7.3 – six security issues has been fixed 03/06/2017
Let's make things clear with these intruder activities that happens every day with any website. How are they dangerous? What tools or plugin can mitigate them? What are chances that we can do that successfully?
WP Cerber allows you to easily enable desktop and mobile notifications and get all those notifications from your WordPress instantly and for free. In a desktop browser, you will get popup messages even if you logged out of your WordPress. Last posts from WordPress security blog Brute-force, DoS, and DDoS attacks – [...]