# Your WordPress site has been hacked

> Redirects to an unknown site, pharmacy or casino pages indexed under your domain in Google, a warning from your host: fixing a WordPress hack means finding the entry point, not just deleting the visible files.

- Source canonique : [https://allaux.fr/en/wordpress-woocommerce/site-pirate](https://allaux.fr/en/wordpress-woocommerce/site-pirate)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Delete nothing yet: the injected files and the server access logs are what let you find the way in. Take a full copy of the files and the database before anything else, then open Users > All Users and look for an administrator account you never created. Finally, search wp-content/uploads for .php files — it should hold media only.

## Signs pointing to a hack

- Automatic redirect to another site when opening certain pages
- Google shows a "this site may be hacked" warning in search results
- Unknown pages indexed in Google under your domain (pharmacy, casino, counterfeit goods)
- A new admin user appears in WordPress that you didn’t create
- Host alert for mass spam sending or suspicious activity
- Unknown PHP files in wp-content/uploads, a folder meant to hold only media

## How I work

1. **Containment** — I first limit access to the site or switch it to maintenance mode to stop active exploitation, without erasing evidence useful for diagnosis.
2. **Finding the entry point** — I check for outdated plugins and themes, pirated ("nulled") extensions, weak passwords, and access logs to identify how the intrusion happened.
3. **Full cleanup** — I remove injected files, fraudulently created admin accounts, and compare the WordPress core files to a clean version to spot unauthorised changes.
4. **Closing the flaw** — I update or replace what allowed the intrusion. Cleaning up without fixing the flaw guarantees reinfection within days.
5. **Post-cleanup check** — I check for any remaining backdoors and request a re-review from Google Search Console if the site had been flagged.

## How the intrusion usually happens

The vast majority of WordPress hacks come through an outdated plugin or theme with a known, published flaw, or through a "nulled" extension downloaded for free outside the official repository, which often carries a backdoor from the moment it’s installed.

Once access is gained, injected files typically hide in wp-content/uploads (a folder normally reserved for media, often less closely watched) or mimic core file names to go unnoticed. An extra admin account is sometimes created directly in the database, bypassing the interface, to keep access even after a first superficial cleanup.

Login credentials and the security keys defined in wp-config.php should be regenerated after an incident, to invalidate any session or access that may have been copied during the intrusion.

## Deleting the visible files isn’t enough

> A cleanup that stops at the obviously suspicious files often leaves an active backdoor. Without identifying and closing the entry point, the site is reinfected within days.

## Worth reading next

- **What to do in the first two hours** — The order of actions when a hack has just been found. ([/securite/que-faire-dans-les-deux-heures](/securite/que-faire-dans-les-deux-heures))
- **Checking whether my site is compromised** — The signs to look for before calling it a false alarm. ([/securite/verifier-si-mon-site-est-compromis](/securite/verifier-si-mon-site-est-compromis))
- **Cleaning an infected site** — What a full clean-up involves, files and database. ([/securite/nettoyer-un-site-infecte](/securite/nettoyer-un-site-infecte))
- **Staying protected after a clean-up** — Without this step, the same hole gets reused within days. ([/securite/se-proteger-apres-un-nettoyage](/securite/se-proteger-apres-un-nettoyage))

## FAQ

### Have I lost my customer data or orders?

In most cases no, the hack aims to inject content or redirect traffic, not wipe the database. I systematically check data integrity during cleanup.

### Do I need to notify my customers if data may have been exposed?

If the intrusion may have exposed personal data (customer accounts, addresses), a declaration to the CNIL may be required under the GDPR. I help you work out exactly what was exposed to inform that decision.

### How long does cleaning up and securing the site take?

A basic cleanup usually takes a day. Finding a well-hidden flaw or a persistent backdoor can take longer to investigate.

### What access do I need to give you?

FTP or SSH access, database access, and WordPress admin access if a clean account is still available.

### How do I stop this happening again?

Regular plugin and theme updates, removing any pirated extensions, strong passwords, and monitoring for modified files. I can set this up as ongoing maintenance.
