Maybe late for this thread but this is absolutely wrong. If someone has access to your CPanel, changing anything else (db info, db password, Wordpress pw etc) is futile. Ditto for restoring from a backup.
As pretty much everyone said, since this is the only site on that shared hosting, contact hosting provider, have them reset and you are good to go.
+1 on finding out how it was hacked but since they accessed your cpanel there are essentially 4 options
1) you are using an insecure password that you are also using somewhere else.................
2) You logged in from an infected computer or using an insecure connection and your password was captured
3) You have this password in an email or something of the sort that was breached
4) Your host was somehow breached or they do not have Brute force protection at the server level