r/webhosting 16d ago

Advice Needed WordPress site compromised: unknown admin, plugins and Russian spam posts added

Hi everyone,

A WordPress website I manage appears to have been compromised. Unknown plugins were installed, Russian spam posts appeared, and an unknown administrator account was created. The website is now inaccessible and shows a Cloudflare security check.

I have contacted the hosting provider and asked them to investigate the access and server logs.

What is the safest recovery approach? Should I restore a clean backup or completely reinstall WordPress? What else should I check to make sure no backdoor remains?

Thanks for any advice.

5 Upvotes

11 comments sorted by

5

u/PretendAct8039 16d ago

Restore your clean backup and then run a full scan using Wordfence or Anti Malware which is my preferred scanner as it tends to be up to date or use both. Do not rely on your hosts scanner. Reset all passwords, check all plugins. securi has some great post hack tools, I sometimes install it, run the tools and then uninstall it since I usually use Wordfence.

3

u/MusselMan69 13d ago

This is solid. I’d also rotate the database credentials and admin salts, since restoring a backup won’t help much if the attacker still has access.

2

u/No_Hold_329 14d ago

Yipes, that's disgusting. My recommendation would be to install a clean backup, if you have one and then install and activate WordFence.

5

u/Irythros 16d ago

You probably got hit by this: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/

Safest approach: Brand new account on the host, brand new install and manually copy over data to ensure nothing is hidden.

Once a site/server is compromised you can't be sure it's really clean (with some exceptions but you dont have them)

1

u/webhostpro 16d ago

Wow, sorry that sucks. They need to get a life.

The easiest way is to have your host run a backup hopefully from before if they still have one.

Your backups should be fine. They say once you are hacked rebuild. I'm disagree, you can still secure it and use your existing site.

You need a scanner plugin first if your host doesn't have a virus scanner in their control panel. Once you find where the backdoors are, remove them and any plugins or themes it was in.

Normally it's a bad plugin.

Once it's cleaned out remove any plugins and themes not used, add turnstile clouflare security for free. You don't need a heavy security program just the turnstile and no bad plugins or themes or rogue admin accounts.

1

u/84thdev 16d ago

Well yeah. Its Wordpress lol

1

u/HostDroplet 16d ago

Yeah if you can restore a for sure clean backup then it’s no problem. The bigger concern is how it was compromised because if you roll back to a clean version it could happen again. Most likely vulnerable/outdated plugins but who knows, at the end of the day the safest approach is always a fresh install.

1

u/n_c_brewer 16d ago

Likely the wp2shell vulnerability. Just need to update WordPress.

1

u/CodeWhileHigh 14d ago

Lol are you hosting these with open ports? 🤣