Reading view

Can anyone share some advice on dealing with a hacked WordPress website?

My website recently started having some issues:

  • Random .html files containing gambling content are being generated in wp-includes and some plugin directories
  • A user named tester appeared, and I have no idea where it came from
  • A strange GTM code was injected into the theme's header.php and footer.php
  • Some unknown PHP files were also found

What I've done:

  • Changed all passwords for Hosting, cPanel, SSH, FTP, Database, and WordPress; enabled 2FA and replaced the Security Keys/SALTs
  • Replaced wp-admin and wp-includes with fresh copies downloaded directly from WordPress
  • Updated all plugins/themes and removed suspicious files
  • Ran Wordfence in High Sensitivity mode and scanned with Imunify360

However, the website is still being reinfected with HTML files, PHP files, and the GTM code.

I'm not a technical person, so I'm not sure what else I should check or where to start.

If anyone has experience dealing with a WordPress site that keeps getting reinfected, I'd really appreciate some guidance.

Thanks!

submitted by /u/minhnana
[link] [comments]
  •  
❌