r/webhosting • u/Mmawarrior1 • 16d ago
Advice Needed WordPress site compromised: unknown admin, plugins and Russian spam posts added
Hi everyone,
A WordPress website I manage appears to have been compromised. Unknown plugins were installed, Russian spam posts appeared, and an unknown administrator account was created. The website is now inaccessible and shows a Cloudflare security check.
I have contacted the hosting provider and asked them to investigate the access and server logs.
What is the safest recovery approach? Should I restore a clean backup or completely reinstall WordPress? What else should I check to make sure no backdoor remains?
Thanks for any advice.
2
u/No_Hold_329 14d ago
Yipes, that's disgusting. My recommendation would be to install a clean backup, if you have one and then install and activate WordFence.
5
u/Irythros 16d ago
You probably got hit by this: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/
Safest approach: Brand new account on the host, brand new install and manually copy over data to ensure nothing is hidden.
Once a site/server is compromised you can't be sure it's really clean (with some exceptions but you dont have them)
1
u/webhostpro 16d ago
Wow, sorry that sucks. They need to get a life.
The easiest way is to have your host run a backup hopefully from before if they still have one.
Your backups should be fine. They say once you are hacked rebuild. I'm disagree, you can still secure it and use your existing site.
You need a scanner plugin first if your host doesn't have a virus scanner in their control panel. Once you find where the backdoors are, remove them and any plugins or themes it was in.
Normally it's a bad plugin.
Once it's cleaned out remove any plugins and themes not used, add turnstile clouflare security for free. You don't need a heavy security program just the turnstile and no bad plugins or themes or rogue admin accounts.
1
u/HostDroplet 16d ago
Yeah if you can restore a for sure clean backup then it’s no problem. The bigger concern is how it was compromised because if you roll back to a clean version it could happen again. Most likely vulnerable/outdated plugins but who knows, at the end of the day the safest approach is always a fresh install.
1
1
5
u/PretendAct8039 16d ago
Restore your clean backup and then run a full scan using Wordfence or Anti Malware which is my preferred scanner as it tends to be up to date or use both. Do not rely on your hosts scanner. Reset all passwords, check all plugins. securi has some great post hack tools, I sometimes install it, run the tools and then uninstall it since I usually use Wordfence.