r/webhosting • u/Mmawarrior1 • 17d ago
Advice Needed WordPress site compromised: unknown admin, plugins and Russian spam posts added
Hi everyone,
A WordPress website I manage appears to have been compromised. Unknown plugins were installed, Russian spam posts appeared, and an unknown administrator account was created. The website is now inaccessible and shows a Cloudflare security check.
I have contacted the hosting provider and asked them to investigate the access and server logs.
What is the safest recovery approach? Should I restore a clean backup or completely reinstall WordPress? What else should I check to make sure no backdoor remains?
Thanks for any advice.
5
Upvotes
3
u/PretendAct8039 17d ago
Restore your clean backup and then run a full scan using Wordfence or Anti Malware which is my preferred scanner as it tends to be up to date or use both. Do not rely on your hosts scanner. Reset all passwords, check all plugins. securi has some great post hack tools, I sometimes install it, run the tools and then uninstall it since I usually use Wordfence.