{"id":413,"date":"2013-01-25T19:26:51","date_gmt":"2013-01-25T19:26:51","guid":{"rendered":"https:\/\/puvox.software\/?p=413"},"modified":"2024-02-15T08:28:23","modified_gmt":"2024-02-15T08:28:23","slug":"what-should-you-do-if-your-wordpress-web-site-was-hacked","status":"publish","type":"post","link":"https:\/\/puvox.software\/blog\/what-should-you-do-if-your-wordpress-web-site-was-hacked\/","title":{"rendered":"What should you do if your WordPress web-site was hacked."},"content":{"rendered":"<div class=\"default-content-clss content_413 type_post \"><div class=\"wpLinkHere\">Remember short-link to MUST-HAVE WP plugins: <a href=\"https:\/\/puvox.software\/wordpress\">puvox.software\/wordpress<\/a>&nbsp; <\/div><div style=\"clear:both;\"><\/div><h2 style=\"text-align: center;\">Restore\/Recover site after hacking<\/h2>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-1932 size-large\" src=\"https:\/\/puvox.software\/wp-content\/uploads\/2017\/01\/wordpress-1024x1024.png\" alt=\"wordpress hacked\" width=\"730\" height=\"730\" srcset=\"https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-1024x1024.png 1024w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-400x400.png 400w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-150x150.png 150w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-300x300.png 300w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-768x768.png 768w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-270x270.png 270w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-1200x1200.png 1200w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress-60x60.png 60w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2017\/01\/wordpress.png 1920w\" sizes=\"(max-width: 730px) 100vw, 730px\" \/><\/p>\n<p>Countless of <strong><a href=\"http:\/\/wordpress.org\">WordPress CMS<\/a><\/strong> based websites are hacked every day. This happens, because WP is open-source and all of it&#8217;s plugins too, so, many bad people use the &#8220;holes&#8221; and &#8220;issues&#8221; for their advantage and hack websites. In case you were a victim,\u00a0you have to do the following steps.<span style=\"color: #ff0000;\">\u00a0(Note, if you miss any step, your site will possibly remain hacked):<\/span><\/p>\n<ul>\n<li>At first, report the malicious plugin\/theme to <strong>plugins[@]wordpress.com<\/strong> or theme\/plugin developer company itself . Also, post that issue on WordPress forums, to warn others too.<\/li>\n<li>Delete that file immediately.<\/li>\n<li>Delete all suspicious **plugins** and **themes**. Remember the list of TRUSTED plugins you have installed and TRUSTED theme name (continue reading).<\/li>\n<li>Backup database (export to PC) and delete database from MYSQL server.<\/li>\n<li>Change password and database name of MYSQL server.<\/li>\n<li>(Not required, but strongly recommended): Change your WP login password. If you used that password somewhere else, change everywhere (because your password may have been grabbed already)<\/li>\n<li>Backup only <strong><code>wp-content\/uploads<\/code><\/strong> folder (if you have custom theme or something, backup it too), and delete everything from <strong><code>public_html<\/code><\/strong>.<\/li>\n<li>Check uploads (or other folders you backed-up), if there is any <strong><code>.php<\/code><\/strong>\u00a0or server-side files inside that, it is is clean, then put that folder back to site.<\/li>\n<li>Now you have to check your exported DATABASE(SQL) file carefully. see if there are extra\/suspicious tables or EXTRA USER added, or some hackable cron job created.<\/li>\n<li>Import the revised SQL database back to newly created database (with different username and password as I&#8217;ve said), but:\u00a0 before importing, you can replace your admin password from <code>wp_users<\/code> table with <code>$P$B1oYQ3msvVDfFRDwiCY6lViBGmiXMT\/<\/code> (this is password <code><strong>a<\/strong><\/code>. you should change it as soon as you enter your site first time).<\/li>\n<li>Reinstall clean WordPress installation on your site (if you use old version of WP, please install <strong>NEWEST VERSION<\/strong>).<\/li>\n<li>Install only those &#8220;Trusted&#8221; plugins and theme.<\/li>\n<\/ul>\n<p>These are short description of necessary steps to recover your site after hack. It may be a hard process somehow, but if you want safety, you should do this. <strong>Otherwise, you will still remain hacked!<\/strong><\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<div class=\"default-content-clss excerpt_413 type_post \"><p>Remember short-link to MUST-HAVE WP plugins: puvox.software\/wordpress&nbsp; Restore\/Recover site after hacking Countless of WordPress CMS based websites are hacked every day. This happens, because WP is open-source and all of<a class=\"excerpt-read-more\" href=\"https:\/\/puvox.software\/blog\/what-should-you-do-if-your-wordpress-web-site-was-hacked\/\">(Continue Reading)<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":2578,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[13,8],"tags":[],"class_list":["post-413","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-website","category-wordpress"],"_links":{"self":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/posts\/413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/comments?post=413"}],"version-history":[{"count":1,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/posts\/413\/revisions"}],"predecessor-version":[{"id":5546,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/posts\/413\/revisions\/5546"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/media\/2578"}],"wp:attachment":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/media?parent=413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/categories?post=413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/tags?post=413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}