RM Logo
WordPress Website Hacked, Here’s What Happened and How I Fixed It | Robert Mullineux

Tips For Fixing a Hacked WordPress Website

The Silent Dangers Lurking in Outdated Plugins

Did You Know…

While it’s difficult to pinpoint an exact number of WordPress hacks per year, security research consistently reveals a large number of vulnerabilities and incidents. For example, Patchstack reported 7,966 vulnerabilities in 2024, which is a significant increase from the 5,947 reported in 2023. Additionally, Forbes reported that around 30,000 websites are hacked every day, and a significant portion of those are likely WordPress sites which have little to no security optimisation.

Restoring a Hacked WordPress Website

I recently had a client reach out in a panic, advising that her WordPress website had been hacked. Pages were redirecting to suspicious gambling sites, and malicious code had been injected across the site. It was a mess, and understandably, she was overwhelmed.

After a thorough investigation, I uncovered the root of the issue: an outdated plugin had introduced a backdoor vulnerability, and there was also an active XML-RPC exploit in play.

These weaknesses gave the hacker access to rewrite the site’s .htaccess file, allowing them to hijack traffic and redirect it to external spam domains. It’s a tactic I’ve seen before—and sadly, it’s not uncommon.

Once I identified the compromised components, I began the clean-up process:

  1. Removed all injected malicious code (SQL Injection) from the database and theme files
  2. Cleaned and restored the .htaccess file to remove redirections
  3. Deactivated and removed the vulnerable plugin, replacing it with a secure alternative
  4. Disabled XML-RPC access, a common backdoor entry point for attackers
  5. Installed and configured a premium security firewall to harden the site against future attacks
  6. Updated all plugins, themes, and WordPress core to the latest versions
  7. Scheduled regular backups and set up malware scanning

The site was restored within a few hours, and the client could breathe again. But it was a stark reminder of how easily a webite site can be compromised if not properly secured.

Common Causes of WordPress Hacks

WordPress is one of the most popular content management systems in the world, which also makes it a frequent target for hackers. Here are some of the most common vulnerabilities I see:

Outdated Plugins and Themes

Many site owners neglect to update plugins and themes regularly. Developers patch vulnerabilities in new releases—but if your site is still running outdated versions, you’re leaving the door wide open.

Weak Passwords and No 2FA

Simple passwords are an open invitation to brute-force attacks. Without two-factor authentication (2FA), it’s far too easy for someone to gain admin access.

XML-RPC Exploits

While XML-RPC is designed to allow remote access, it’s often abused by attackers to carry out DDoS attacks or brute-force logins.

No Firewall or Malware Scanning

Without a firewall, your site is exposed to a constant stream of automated attacks. Malware scanners help detect threats early—before they cause serious damage.

Poor Hosting Environment

Some budget hosting platforms don’t offer adequate server-level protection, leaving sites vulnerable despite good plugin and theme practices.

Unprotected Admin Areas

If your /wp-admin login page is public and unprotected, bots and hackers can attempt thousands of login attempts without being blocked.

Securing your WordPress website isn’t just about protecting your brand or avoiding downtime—it’s also about protecting your visitors and their data. If your site is compromised, you risk exposing customer information, damaging your reputation, and potentially facing legal consequences.

When a site is hacked, the damage can ripple far beyond a single page or redirect. It can affect your SEO rankings, your customer trust, and even your ability to run ads if your domain is flagged.

This is why I always stress to clients: security is not optional. It’s essential.

If you’re unsure whether your website is properly secured or worse, if you think it may have already been compromised; I can help. I offer professional WordPress security audits, hack clean-ups, and ongoing website maintenance support to make sure your site stays safe, fast, and protected. Reach out today to schedule a website health check or to chat about securing your site before it becomes a target.

Facebook
Twitter
Reddit

Get In Touch