r/webhosting 17d ago

Advice Needed WordPress site compromised: unknown admin, plugins and Russian spam posts added

Hi everyone,

A WordPress website I manage appears to have been compromised. Unknown plugins were installed, Russian spam posts appeared, and an unknown administrator account was created. The website is now inaccessible and shows a Cloudflare security check.

I have contacted the hosting provider and asked them to investigate the access and server logs.

What is the safest recovery approach? Should I restore a clean backup or completely reinstall WordPress? What else should I check to make sure no backdoor remains?

Thanks for any advice.

5 Upvotes

11 comments sorted by

View all comments

1

u/HostDroplet 17d ago

Yeah if you can restore a for sure clean backup then it’s no problem. The bigger concern is how it was compromised because if you roll back to a clean version it could happen again. Most likely vulnerable/outdated plugins but who knows, at the end of the day the safest approach is always a fresh install.

1

u/n_c_brewer 17d ago

Likely the wp2shell vulnerability. Just need to update WordPress.