How to Recover and Secure a Hacked WordPress Website: A Step-by-Step Technical Guide
JAKARTA — WordPress remains the world’s most widely used Content Management System (CMS), powering millions of websites globally. However, its immense popularity also makes it a primary target for cyberattacks, including spam injection, phishing schemes, and defacement attacks.
While the core platform is inherently secure when kept updated, vulnerabilities often arise from outdated themes, unpatched plugins, or the use of pirated (nulled) software. For website owners facing a security breach, technical experts have outlined a structured recovery protocol to restore site integrity without losing critical data.
Before initiating any remediation steps, administrators must perform a full system backup of existing databases and files to preserve current data. Technical requirements mandate checking hosting resources to ensure adequate disk space and inode availability. A single compromised installation typically requires at least 120 MB of free storage and 5,000 inodes to facilitate file operations during cleanup.
To restrict external access and prevent further payload execution, administrators must place the site in isolation. This is accomplished by accessing the cPanel File Manager, enabling hidden files (Show Hidden Files), and creating a temporary directory outside the public_html root folder to store affected site files.
Deployment of Clean Core Files
To ensure complete removal of compromised system files, site operators should temporarily put the site into maintenance mode by creating a .maintenance file in the primary directory.
The recovery process involves fetching a fresh copy of the official WordPress core package (wordpress.org/latest.zip), extracting the clean core files directly into the web root folder, and replacing the compromised system core.
To preserve original site assets without carrying over malicious scripts, only specific directories must be restored:
Uploads Directory: Transfer only the
wp-content/uploadsdirectory from the compromised backup.Configuration: Copy the original
wp-config.phpfile to retain database connections.Themes and Plugins: Under no circumstances should old theme or plugin folders be transferred directly, as these are common vectors for backdoor re-infection.
Instead, administrators must re-download fresh, authentic packages directly from official repositories or verified developers and reinstall them individually.
Final Restoration and Security Verification
Once clean core files, media uploads, configurations, and verified extensions are restored, administrators can remove the .maintenance file to bring the website back online.
Cybersecurity researchers emphasize that a significant percentage of WordPress compromise incidents stem from the use of "nulled" (pirated) premium themes and plugins. Attackers frequently embed obfuscated PHP scripts, web shells, and hidden administrative backdoors into freely distributed commercial plugins, allowing unauthorized remote execution long after installation.
Beyond post-hack recovery, website administrators are strongly advised to implement proactive hardening strategies, including:
Two-Factor Authentication (2FA): Implementing 2FA on login endpoints (
wp-login.php) to mitigate brute-force attempts.Web Application Firewalls (WAF): Utilizing security plugins or DNS-level firewalls (such as Cloudflare or Sucuri) to block malicious traffic patterns.
Automated Off-site Backups: Scheduling daily or weekly backups stored in remote cloud storage separate from the hosting provider.
Principle of Least Privilege: Restricting administrative access and enforcing strong password policies across all user roles.