Yeah as mentioned above your site most likely got hacked.
If you use nulled plugins or themes, that's probably the reason you were voulnerable. It could also be a problem if you didn't update your plugins or theme.
Now it's all about damage control.
Do the following:
- Delete any nulled plugins or themes
- Delete any plugins or themes you didn't add yourself
- Update any plugins or themes that are out of date
- Add the Malcare Plugin, run a scan and follow the instructions. (Remove everything in regards to malware/viruses you can find).
- Add the Wordfence Plugin, run a scan and follow the instructions. (Remove everything in regards to malware/viruses you can find). Select the highest security settings for now (use google if you're not familiar with wordfence).
- Add the wps hide login plugin and change the login-site
- Change your password & delete any users you didn't create yourself
- Delete any posts you didn't write.
Depending on your host you might be able to check which IP adresses accessed your sites dashboard. If you can find the IP adress of the hacker, add it to the block list in word-fence (This is just an additional measure, it won't really protect you for good since you can use a proxy or vpn).
Now even after this, it is totally possible that your site still can be accessed by the hackers. If you really wanna clean out your site for sure, you should use a paid service because they have way more experience than any blackhatworld or youtube guide you will find. (Wordfence & Sucuri offer cleanups for hacked sites).
Before you use a paid service however, you should check your rankings, especially recent posts. If you have disappeared for keywords where you ranked relatively high (1st till 3rd result) then you most likely got penalized (if those links are too spammy / contain viruses/malware).