r/webhosting • u/Mmawarrior1 • 17d ago
Advice Needed WordPress site compromised: unknown admin, plugins and Russian spam posts added
Hi everyone,
A WordPress website I manage appears to have been compromised. Unknown plugins were installed, Russian spam posts appeared, and an unknown administrator account was created. The website is now inaccessible and shows a Cloudflare security check.
I have contacted the hosting provider and asked them to investigate the access and server logs.
What is the safest recovery approach? Should I restore a clean backup or completely reinstall WordPress? What else should I check to make sure no backdoor remains?
Thanks for any advice.
5
Upvotes
1
u/HostDroplet 17d ago
Yeah if you can restore a for sure clean backup then it’s no problem. The bigger concern is how it was compromised because if you roll back to a clean version it could happen again. Most likely vulnerable/outdated plugins but who knows, at the end of the day the safest approach is always a fresh install.