WordPress site hacked and redirecting to another site: how to clean it

Your site sends visitors to a spam, scam or betting page. The attacker added code that runs on every visit. Often it hides from you when you are logged in, so you only see it on your phone or from Google.

What to do, in order

  1. Take a full backup first, files and database, even though it is infected. You may need it.
  2. Change every password: WordPress admins, hosting panel, FTP and database. Delete admin users you do not recognise.
  3. Check the two settings that get changed most. In Settings, General, the WordPress Address and Site Address must be your own domain. In the database, look at siteurl and home in the wp_options table.
  4. Look at the usual hiding places: the .htaccess file in the main folder (rewrite rules pointing elsewhere), the top of wp-config.php and index.php, and your theme's functions.php and header.php. Long lines of scrambled text with eval or base64_decode are the sign.
  5. Replace WordPress core. Dashboard, Updates, Reinstall. Then delete and reinstall every plugin and theme from the official source. Remove any you no longer use.
  6. Search the database for <script in posts and options. Injected scripts often sit in post content or widget text.
  7. Ask Google to recheck. If Search Console shows a security warning, request a review once the site is clean.

If the redirect keeps coming back, send me the address and I will find where it is loading from.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.