     / Plain-English guides](https://getfullstacksolutions.com/guides/index.html)/ My WordPress site got hacked. Now what?   Security · people search: “My WordPress site got hacked. Now what?”

# My WordPress site got hacked. Now what? The panic is normal. The response shouldn't be. Here's the calm, step-by-step playbook — and how to know if you need a professional. Plain English · no jargon · 4-minute read By Rodrigo Valenzuela Iturrieta](https://getfullstacksolutions.com/about/index.html), the engineer who does the work · Published March 2, 2026 · Updated September 20, 2026 Part of **Security & Emergencies](https://getfullstacksolutions.com/services/security/index.html) — read first, then fix it in 48h.   Copy link   Print   Share  Know someone with this exact problem? Pass it on — no email gate.       Your WordPress site is showing pop-ups you didn't add, redirecting to strange pages, or your host has suspended it for 'malicious activity'. Take a breath. Hundreds of thousands of WordPress sites get hacked every year, and almost all of them can be put right. What matters is how you respond in the first hours — that decides whether you lose the site, the ranking, or customer data.

## Check these first, yourself

- Change every password and key you can reach now: hosting — The service that runs your site on a server; the plan you pick decides your speed ceiling and your crash risk., admin users, FTP — File Transfer Protocol — the old way of moving files to a server; left open and unencrypted, attackers love it., payment accounts.
- Do NOT wipe and reinstall WordPress yet. You'll lose the evidence of how they got in, and you may destroy the data you need.
- Log into your host and look for the last-modified dates on your theme and upload folders. Recently modified files are the fingerprints.
- Enable two-factor — A second proof of identity (a code from your phone) on top of the password, so a stolen password isn't enough. on your admin account and every email account connected to the site.

### When to call a rescue instead of doing it yourself If you can see malware — Malicious software planted on your site; it can redirect visitors, steal data, or get you blacklisted by Google., don't trust a one-click 'cleaner' plugin — that's how sites get hacked again two weeks later. A proper cleanup finds and closes the backdoor that let them in, not just the obvious files. A Hack Cleanup & Forensics rescue does exactly this in 48 hours and leaves you a written explanation you can actually understand.

### Should you fix it yourself or call a rescue?   **Have you tried the free fixes (images, caching, plugins)?If yes and it's still slow → the problem is deeper.     **Is your hosting or server the bottleneck?Shared hosting, old PHP, no object cache → server-level problem.      **Yes → Speed Rescue Fixed in 48h · from $2,000 ](https://getfullstacksolutions.com/rescue/speed/index.html)   **Not sure → Send symptom We'll diagnose for free ](https://getfullstacksolutions.com/contact/index.html)

## Still have questions?  Should I pay the ransom they ask on the hack screen?Almost never. Extortion screens on WP sites are usually automated malware looking for a quick payout — they rarely restore anything, and paying tells the attacker you're worth revisiting.Can I just restore an old backup?Only if the backup is clean — and the backdoor can live in files you restored. Once the site is restored, the hackers can stroll back in through the same door. The infection has to be removed at the source.        Skip the diagnosis

## Get this fixed in 48 hours, flat rate Same problem, less sleep lost. One of these rescues maps directly to what you're dealing with.    security **Hack Cleanup & Malware Removal $3,500 · 48 hours ](https://getfullstacksolutions.com/rescue/hack-cleanup/index.html)  infrastructure **Backup System & Restore Test $2,000 · 48 hours ](https://getfullstacksolutions.com/rescue/backup/index.html)  security **Domain Hijack Recovery $3,500 · 48 hours ](https://getfullstacksolutions.com/rescue/domain-hijack/index.html)      Keep reading

## Related plain-English guides More of the questions business owners actually search — same plain-English style, same no-jargon promise.    Security guide **SSL Certificate Expired — Fix It Fast An expired or mismatched certificate throws a full-page 'Not secure' warning that scares customers off. Here's what broke and how fast it can be fixed. Read the plain-English guide → ](https://getfullstacksolutions.com/guides/ssl-expired/index.html) Security guide **Domain Hijacked: How to Recognize It & Get It Back The domain is your whole identity on the internet — email, site, and all. When it's taken over, minutes matter. Here's the playbook. Read the plain-English guide → ](https://getfullstacksolutions.com/guides/domain-hijacked/index.html) Security guide **Website Blacklisted — 'Deceptive Site Ahead' A red 'Deceptive site ahead' or 'This site may harm your computer' page is a blacklist, not a hack in itself. Here's what put you on it and how to get off. Read the plain-English guide → ](https://getfullstacksolutions.com/guides/site-blacklisted/index.html)

## Don't want to become an expert in this? Send the symptom — get a flat-rate ticket and a plain-English plan within 12 hours. Start the Rescue
