Wordpress site hacked recovery

Blackout188

Newbie
Joined
May 7, 2020
Messages
44
Reaction score
10
My site was attacked with js injection malware of some sort that caused infinite redirect loop. Good thing that I have an automatic backup set up so I didn't lose much content.

I had woofence and Cloudflare installed and I thought these would prevent this type of attack, which obviously did not work.

My question is that, is there an easier way to remove malware injected than fresh install and backup recovery and is there additional tools that can prevent action like this. (Yes, I read through the WordPress blogs on tips and guide)
 
which backup tool you were using ? are you backup files on same server
 
If this happened with me, I always contact hosting company to fix this issue for me and they always fix it for me.

My hosting company told me to use virus scan from Cpanel to resolve it. And it didn't work at all. I just had to do all the heavy lifting myself. Good thing I know the basics lol
 
which backup tool you were using ? are you backup files on same server
Updraft, not on the same server, it would get compromised I feel. I had it saved locally and on a separate cloud.
 
My site was attacked with js injection malware of some sort that caused infinite redirect loop. Good thing that I have an automatic backup set up so I didn't lose much content.

I had woofence and Cloudflare installed and I thought these would prevent this type of attack, which obviously did not work.

My question is that, is there an easier way to remove malware injected than fresh install and backup recovery and is there additional tools that can prevent action like this. (Yes, I read through the WordPress blogs on tips and guide)
Backup your site through Updraft Plus and you can restore from the backup in just one click, also look at installing WordFence to prevent any similar attacks
 
My site was attacked with js injection malware of some sort that caused infinite redirect loop. Good thing that I have an automatic backup set up so I didn't lose much content.

I had woofence and Cloudflare installed and I thought these would prevent this type of attack, which obviously did not work.

My question is that, is there an easier way to remove malware injected than fresh install and backup recovery and is there additional tools that can prevent action like this. (Yes, I read through the WordPress blogs on tips and guide)
There are a lot of different ways to attack your site, and software like WordFence can only do so much. a lot of times sites get infected because they installed a free plugin or theme. If you only install plugins/themes from official sources only, you're pretty much fine.
 
If this happened with me, I always contact hosting company to fix this issue for me and they always fix it for me.

Hosting companies can't do a shit in this case. they run a normal scan but don't remove malware/hacking activity form your site. It normally happens due to nulled plugins and themes which is not advisable to use.
I think the better option would be to reinstall the WordPress and restore it from your saved backup.
 
There are a lot of different ways to attack your site, and software like WordFence can only do so much. a lot of times sites get infected because they installed a free plugin or theme. If you only install plugins/themes from official sources only, you're pretty much fine.
It makes sense, the majority of my plugin are from official sources. the attack could result from the few that are not. It's too expensive to purchase them all, but I'm now paying the price I guess.
 
It makes sense, the majority of my plugin are from official sources. the attack could result from the few that are not. It's too expensive to purchase them all, but I'm now paying the price I guess.
Yeah, sometimes it's better to dig the WordPress repo for alternatives when you just can't afford to buy a plugin or a theme.
 
The lesson here is always to keep backups and never use null/cracked plugins.

Good hosts will typically fix it for you. (The ones with Cpanel usually aren't one of them that will.)
 
Either pay for plugins and themes or keep upto date backup of website and keep checking every post manually.
 
I do want to migrate to VPS hosting that is reliable down the road, but I do need some sort of control panel for usability. Any recommendations on that front?
 
i did not backup the site and now i'm in trouble i think lool daaaamn
 
i did not backup the site and now i'm in trouble i think lool daaaamn
If you can't find a backup, and you're goosed. Don't worry about it. It will be the last time you have this problem! :) Everyone who takes good backups has lost their stuff already at some point.
 
If you can't find a backup, and you're goosed. Don't worry about it. It will be the last time you have this problem! :) Everyone who takes good backups has lost their stuff already at some point.
hahahaa the problem is i was planing to backup the site since a month i was procrastinating for days also the weather is too hot i can't think clearly i will try to fix this if not we al learn the hard way
 
hahahaa the problem is i was planing to backup the site since a month i was procrastinating for days also the weather is too hot i can't think clearly i will try to fix this if not we al learn the hard way
"But those woulda-coulda-shoulda all ran away and hid from one little did." - Shel Silverstein
 
Back
Top