forumNew topic

Is our WordPress site hacked or just a broken plugin? How can we tell if someone's inside?

ÜÜmit B***Expert
Job title
System support specialist
Sector
Cosmetics
Organization type
medium-sized business
Joined
Apr 2025
Message
15
#1

We run an industrial packaging wholesale business based in Frankfurt. On our WordPress site which we've been using for four years, some really annoying anomalies started popping up last night. The store pulls in about 14,000 EUR a month, and several customers reported being redirected to strange external pages during the checkout step. But when we test it ourselves from our office PCs or mobile phones, everything looks completely normal.

When we logged into the admin dashboard, we spotted an unfamiliar email address listed under the admin users. Meanwhile, our freelance developer claims that a shipping tracking plugin update we ran last week messed up the database, and that the redirects might just be down to a corrupted plugin cache. However, this morning, totally unrelated foreign words started showing up under some of our products in Google search results.

Has someone actually breached the system, or are we just dealing with a messy plugin conflict? How can we know for sure? And before we rush to pull the server offline, what kind of initial response and cleanup sequence should we follow to preserve the evidence?

UUğur Y***Veteran
Job title
Clinic manager
Sector
Catering
Organization type
medium-sized business
Joined
Mar 2023
Message
253
Most Helpful#2

Short answer: Finding an unfamiliar admin account and seeing foreign spam terms in search results is 100% a security breach. This cannot be a simple plugin conflict or cache issue. Malicious code has been injected into your site, and there's almost certainly a persistent backdoor in place.

Attackers use filtering rules so search engine redirects or fake payment screens only trigger for specific visitors. Because you're logged in with an admin cookie or browsing from your company IP, you see the clean version, whereas visitors coming from search engines get redirected.

Here's the sequence you should follow for cleanup and evidence collection:

1) Don't panic and start deleting files randomly. First thing: export the raw server access and error logs along with the current database and back them up to a secure external drive. You need these logs to figure out the entry point.

2) Invalidate all security keys (salts) in wp-config.php drop the rogue admin account directly via the database and reset passwords for every authorized user.

3) Overwrite all core WordPress files (wp-admin, wp-includes, and root core files) with fresh copies from the official release. Scan the wp-content/uploads folder and wipe out any .php files in there; executable code should never exist in that directory under normal conditions.

4) Completely delete all plugins and themes then reinstall them cleanly from official repositories. Audit server-level cron jobs and WordPress scheduled tasks to make sure the site won't reinfect itself.

EEsra U***MemberCommunity member
Joined
Feb 2026
Message
160
#3

The reason your customers see it and you don't is User-Agent and Referer filtering. The malicious PHP serves a clean page to direct visitors, but triggers the redirect for traffic arriving from Google searches or external referrers. Check .htaccess and index.php in your site's root directory. You'll likely spot eval, base64_decode, or strange external includes tucked right at the top.

RRamazan T***MemberCommunity member
Joined
May 2024
Message
4
#4

To clean this up without wiping out the evidence, do this: 1) Download the raw access.log for the last 30 days from your hosting panel immediately. 2) Take a full database dump via phpMyAdmin. 3) Note the exact creation timestamp of that suspicious user in the wp_users table. 4) Filter your access logs around that timeframe to see which PHP file or vulnerability received the POST request.

OOrhan D***Expert
Job title
Store associate
Sector
IT services
Organization type
early-stage startup
Joined
Nov 2024
Message
228
#5

Went through the exact same thing last year at our spare parts shop in Hannover. Our dev stalled us for five days claiming it was just a caching glitch. Once Google slapped a security warning on the site, our 4,000 EUR weekly order volume instantly dropped to zero. We ended up paying 850 EUR for an expert cleanup, but clearing the search engine penalty and getting our revenue back took six weeks. Don't waste time.

İİlknur G***VeteranCommunity member
Joined
Nov 2024
Message
80
#6

Your dev's claim that a plugin update broke the database makes zero sense. A broken plugin doesn't create rogue admin accounts in the database or inject spam keywords into Google search snippets. Either they used a nulled plugin from an untrusted source, or they don't want to admit an unpatched vulnerability. Get a third-party security specialist to look at it, not that developer.

TTuğçe M***Member
Job title
Operations manager
Sector
Logistics
Organization type
two-branch business
Joined
Jan 2023
Message
362
#7

The most urgent move right now is putting the site into maintenance mode. If customers are being sent elsewhere at checkout, credit card details might be getting skimmed. Trying to clean up files on a live site will only expose your customers to more risk. Lock down site access in your hosting panel so only your office IP can connect and cut off external traffic immediately.

MMurat Z***Member
Job title
Field sales representative
Sector
Glass
Organization type
chain store
Joined
Jan 2025
Message
27
#8

open up the uploads folder via ftp and search for .php files right away. nothing should ever be in there except images and pdfs. delete anything you find and drop an htaccess file in that folder to block php execution. otherwise even if u clean it up the site will turn back into a zombie tomorrow morning.

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#9

What does your hosting environment look like? Are you on shared hosting or a dedicated VPS? If you're hosting multiple domains or staging environments under the same account, could the attackers have pivoted into the main site through an abandoned subdomain? Do the logs show any cross-directory access?

GGürkanMember
Job title
Energy sector
Organization type
boutique agency
Joined
Nov 2023
Message
94
#10

You mentioned unauthorized redirects on the checkout page. If customers' credit card details or personal data have been compromised by third parties, you may be legally required under German Data Protection Regulations to notify the supervisory authority within 72 hours. Treat this not just as a technical issue, but as a legal matter as well, and make sure server logs are preserved with proper forensic integrity.

VVildan Ş***MemberCommunity member
Joined
Nov 2023
Message
17
#11

Thanks for posting.

VVolkan U***MemberCommunity member
Joined
Feb 2024
Message
56
#12

This thread is archived.

SSena K***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
boutique agency
Joined
Feb 2025
Message
2
#13

You're right.

ZZeynep O***New member
Job title
Business Owner
Sector
Furniture manufacturing
Organization type
family business
Joined
May 2026
Message
1
#14

Let me summarize what's been said so far. Solutions that work at a small scale collapse when you grow; I learned this late.

RRecep N***Member
Job title
IT manager
Sector
Electrical-electronics
Organization type
family business
Joined
May 2025
Message
97
#15

If I understood correctly, you're saying: Taking notes for two weeks yields better results than a six-month estimate.

When we decide without measuring, we always end up in the same place. If you post the result here, it will help others too.

İİbrahim Y***MemberCommunity member
Joined
Feb 2026
Message
3
#16

i didn't know that. if the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

KKemal T***MemberCommunity member
Joined
Feb 2023
Message
4
#17

Absolutely. If I were to add anything: Forgotten test environments are more often the entry point than live systems.

Correct me if I'm wrong.

ÖÖmer O***MemberCommunity member
Joined
Sep 2024
Message
3
#18

Let me write how it's done in practice. If 2FA is on, a stolen password alone is useless.

Hasty decisions become decisions you have to fix six months later. If you have questions, write them; I'll answer as best I can.

MMerve B***New memberCommunity member
Joined
Aug 2026
Message
247
#19

Quick summary for newcomers: Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Of course, it varies if your situation is different.

OOnur T***MemberCommunity member
Joined
Sep 2023
Message
1
#20

There's a trap here let me mention it. Trying to do this alone is the most expensive way.

When making a decision, first look at what data you have on hand. That's all, sorry if I went on too long.

Reply