Wordpress Hacked traffic dropped -> $$$dropped

Stuart94

Registered Member
Joined
Oct 7, 2015
Messages
51
Reaction score
2
So recently my wordpress site was hacked and i don't know why someone would hack my site . I only have like 100-200 visitors per day. BUT anyways the hacker posted porn all over my site and since then everything dropped from having 100 visitors to 30. And i dont know what to do pls someone help i changed the password but i fell like thats not enough.

What should i do to prevent hackers ? and how did this hacker my site ?
 
You can use Two Factor Authentification with for example "Clef" , use Login Limit Plugin and other Plugins like HidemyWP to prevent your website being hacked in the future.

We cannot tell how the Hacker achieved this, there's more than one way. Maybe you had a weak password and he used "Brute Force" to gain access.
 
Hey Stuart,

Running a WordPress Site without protection is f8cking crazy.
I'd suggest to take a look at the following plugins:
  • Wordfence
  • Block Bad Queries (BBQ)
Also, check if you hosting company has been hacked. (Send a ticket support)

Good luck!
 
hey kugundo and iamcholo:) thx for fast help. i will definitaly try out those plugins hope it helps .
but one question i downloaded a plugin can a hacker manipulate a plugin and get acces through that ?
 
PM me your domain name. I'll run a scan on it and check what happened. Usually hackers use a "backdoor" - Nulled theme, outdated plugin or lack of security to access your files. Also, Check your htaccess to see if there is something that shouldn't be there. 90% of the time, they use your domain to spam emails or redirect users to porn site via mobile site.
 
LoginLockDown great tool and WordFence.. if you have money SUCURI is great and cloudflare!
 
As others suggested use WordFence and you will need to research how to do this a bit but change your nicename in the database, this prevents people from finding your username in the source code. And obviously use a strong password as well.
 
You need to also prolly clean your site files too. They prolly have back doors all over.
 
Disable xmlrpc as that is being used to brute force passwords a lot these days. Also rename the default table prefix in the database from wp_ to something else. These are critical steps for hardening wordpress.

By default wordpress is a security nightmare. It's like parking your ferrari in the ghetto and leaving it unlocked with the windows down and keys in the ignition.
 
I got hacked too back in 2013. Damn hackers. Best thing to do is create a support ticket ASAP to your hosting company so they can restore a backup of your site.
And as everybody said here: add security plugins this time!
 
Back
Top