Can anyone share some advice on dealing with a hacked WordPress website?
27 August 2026 at 02:30
My website recently started having some issues:
- Random .html files containing gambling content are being generated in wp-includes and some plugin directories
- A user named tester appeared, and I have no idea where it came from
- A strange GTM code was injected into the theme's header.php and footer.php
- Some unknown PHP files were also found
What I've done:
- Changed all passwords for Hosting, cPanel, SSH, FTP, Database, and WordPress; enabled 2FA and replaced the Security Keys/SALTs
- Replaced wp-admin and wp-includes with fresh copies downloaded directly from WordPress
- Updated all plugins/themes and removed suspicious files
- Ran Wordfence in High Sensitivity mode and scanned with Imunify360
However, the website is still being reinfected with HTML files, PHP files, and the GTM code.
I'm not a technical person, so I'm not sure what else I should check or where to start.
If anyone has experience dealing with a WordPress site that keeps getting reinfected, I'd really appreciate some guidance.
Thanks!
[link] [comments]