My WordPress site got hacked. What should I do?

I would suggest you to find the vulnerability and patch it, Sucuri is a service provider who can do it for you but they are very expensive these days. Alternate way is to find someone fiverr who can do everything at a much lower cost. I have personally done it from someone and he knows his stuff. If you need I can share the link here.
 
Is there anything that could have been done to prevent this? There is a plugin called word fence does anyone know if it is effective in prevent this?
 
There is nothing to be compromised in Cpanel except your Cpanel Password. If you have deleted everything from File Manager ( including the DB ) and changed your CPanel password you should be fine.
Even if you contact your Host all they can do is change your Cpanel password, there is noting to "reset" in Cpanel. ( You can just check the Cron tab if there are some leftovers from the hack ).

There are other things. They can add users, create email accounts, change settings, add scripts, cron jobs etc.

A host can switch you to another shared server, if the server itself was compromised, which will also change the IP and everything else associated. That is what i meant by reset. They can also just put u on a blank install so you dont have to worry about having missed anything.
 
Is there anything that could have been done to prevent this? There is a plugin called word fence does anyone know if it is effective in prevent this?
If the CPanel was compromised, no plugin will help.

On the Wordpress side, I use WPCerber that has a lot of protections for Wordpress, including denying access from any IP that is not whitelisted, changing the default wp-admin and wp-login pages, bruteforce protection etc.
 
Once you identify a hack, one of the first steps you will want to do is lock things down so that you can minimize any additional changes. The first place to start is with your users. You can do this by forcing a global password reset for all users, especially administrators.
 
Maybe late for this thread but this is absolutely wrong. If someone has access to your CPanel, changing anything else (db info, db password, Wordpress pw etc) is futile. Ditto for restoring from a backup.

As pretty much everyone said, since this is the only site on that shared hosting, contact hosting provider, have them reset and you are good to go.

+1 on finding out how it was hacked but since they accessed your cpanel there are essentially 4 options

1) you are using an insecure password that you are also using somewhere else.................
2) You logged in from an infected computer or using an insecure connection and your password was captured
3) You have this password in an email or something of the sort that was breached
4) Your host was somehow breached or they do not have Brute force protection at the server level
ProgressiveWeb, what "is absolutely wrong"? You don't own the power of the words. My advices are good enough for what he needs. Of course, if the cPanel security is compromised, he need to talk with the hosting provider. But, until there, just following my advices his website will be safe enough.
 
ProgressiveWeb, what "is absolutely wrong"? You don't own the power of the words. My advices are good enough for what he needs. Of course, if the cPanel security is compromised, he need to talk with the hosting provider. But, until there, just following my advices his website will be safe enough.

Uhmm no it is wrong. If his CPanel was compromised, doing everything you did, STILL LEAVES HIM COMPROMISED. Hence you are wrong.

Give me your Cpanel password, and do what you did, and I can have you locked back out within about 5 seconds.

Second, installing a plugin will not address the Cpanel vulnerability and figuring that out is primordial or it will keep happening.

Third you don't even address the CPanel issue, hence another reason why the advice is wrong.

Safe enough, is still unsafe.
 
Wordfence is good, and bullet proof security, as well as sucuri.

I put all 3 on WP sites, they all do slightly different things although there is some overlap.
 
Back
Top