That’s very sad that you are experiencing this problem.
You can do the following things to solve the problem :
- Check every folder for a list of known backdoors such as C99.php, C100.php, Weevely.php. (You can do that by grep). And delete anything suspicious.
- Download WPSCAN and run it against your website to see if any known vulnerabilities are present in your website.
- If you are using any nulled plugins or themes. Delete them as soon as possibl.
- Keep your plugins and themes up to date even if you are not using them.
- Always keep a regular backup so that you can restore your website.
I hope my tips help you. And remember, about the known file structure of your website, Security is always better than obscurity.
It doesn’t matter if you have a known file structure until everything you are using is safe.
Cheers!
Related Posts:
- Security issues with WP sites
- What security concerns should I have when setting FS_METHOD to “direct” in wp-config?
- What Are Security Best Practices for WordPress Plugins and Themes? [closed]
- Are WordPress Plugins essential?
- I found this in a plugin. What does it do? is it dangerous?
- What are the common security flaws I need to look for? [closed]
- Disabled plugins are they security holes – rumor or reality?
- What could a hacker do with my wp-config.php
- Why “Contact Form 7” doesn’t update PHPmailer library?
- Secure WordPress paid plugin
- Does WordPress contain “default” anti-SQL injection code that responds with a 404 error?
- What does a security risk in a plugin look like?
- How to generate/update a XML sitemap without plugins?
- WordPress Capabilities: edit_user vs edit_users
- Should we use plugins that aren’t available from the official WordPress site?
- Why allow overriding crucial pluggable functions wp_verify_nonce and wp_create_nonce?
- Should I install plugins to my WordPress installation from web sites having in URL “nulled” or, “null”?
- Disabled plugins are security holes – rumor or reality?
- Should I use RIPS tool to test my themes and plugins?
- Prevent Brute Force Attack
- Why users disable the WordPress update?
- Intercept comment form submit/list by hook/filter
- How many security plugins are too many? [closed]
- Will WordPress username displayed somewhere in the site?
- Upgrading WordPress 4.0 asks for FTP password
- Is revealing just the AUTH_KEY a security issue?
- How Restrict access to admin dashboard by specific static ip?
- When is it useful to use wp_verify_nonce
- Protecting against malicious code in WordPress plugin updates
- How to limit WordPress pages during updates?
- rms_unique_wp_mu_pl_fl_nm.php
- Weird problems after recovery from security breach
- How can we deal with unmaintained plugins with vulnerabilities?
- Security checking in meta_box save is reluctant?
- Escape when echoed
- Preventing BFA in WordPress without using a plugin
- Is it dangerous to install unupdated plugins?
- How can I make uploaded images in the editor load with HTTPS?
- How to stop xmlrpc attacks without disabling component to allow JetPack to work in WordPress?
- WordPress filter that hook after each action/filter hook
- The safest way to automate WordPress backups
- wp_create_nonce function doesn’t work inside a plugin?
- Does WordPress validate inputs to all functions? (such as get_user_meta and insert_user_meta)
- Headers Content-Security-Policy CSP Major Issue
- Nonce failing on form submission
- Why can’t I access my Intranet LDAPS with NADI?
- Stop Plugin Enumeration [closed]
- Hack-Proof OR Security in WordPress — is it real?
- Some one is trying to hack my website, Need guidance [closed]
- Can some vulnerabilities in plugins be exploited even when the plugin is inactive?
- Security and Must Use Plugins
- Is Timthumb still broken? What security measures should be taken?
- Prevent direct access to WordPress plugin assets?
- Is it safe to use admin-ajax.php in the frontend?
- Specific way to allow WordPress users to view their current password? And edit it?
- Too many login attempts
- Is there any pre-existing plugin to track and block IPs with suspicious activity on my site?
- How to prevent plugins from sniffing/stealing other plugins’ options?
- how to activate a plugin inside a theme
- Website show Google Ads when we have no Google Ads linked to our website
- Custom API plugin to execute 3rd party API to retrieve data
- How to deal with Slow HTTP POST (slowloris) vulnerability
- Running multiple security plugins
- how do I secure my WP website from hackers? [closed]
- Chrome Dev Tools console says every page in my blog has link to http://maps.google.com [closed]
- Webservice credential storage [duplicate]
- Regarding plugin security
- Want to modify a Plugin – Tweetily – Can I make it tweet a Custom Field instead of Post Title?
- If I use an alternative login (e.g. CAS or other SSO) plugin, is my site protected from the recent brute force login attempts?
- Is this plugin safe to run?
- Is the Block Bad Queries Plugin Still Relevant?
- WP Insert Post If user refreshes override new post
- Website Captcha Error: The reCAPTCHA wasn’t entered correctly
- Hide plugins and theme from public
- WordPress search shows protected content
- Security of a WordPress Plugin
- Can I disable xml-rpc by setting it to false?
- Help to Create a Simple Plugin to make a post
- Content-Security-Policy implementation with WordPress W3Total Cache plugin installed
- prevent anonymous access to WordPress site (non-admin site)
- Bing/msn bots is heavily requesting random of my website
- “Fire Secure” menu item
- Securing a plugin pop-up window
- https rewrite not working for All in one security Brute force > rename login url
- Redux framework somehow added to my site, can’t locate in plugins
- How can i see/log all requests coming from a registration form (not from the UI)?
- Write mysql credentials in plugin
- Site is continuously accessing by several IPs
- using .htaccess only for wordpress security no plugins
- SWF in wordpress post
- Unwanted Links and Spam WordPress Pages and Posts
- File permissions for wp-minify plugin
- What is the recommended way to be notified of security updates to my plugins? [closed]
- how woocommerce swatch color name when hovered or selected
- How I can hide my wp folders from Inspect Element (Developer Tools)
- How to Find WordPress site has backdoor login Codes
- How to delete Password Protected posts cookies when a user logged out from the site
- How to rename files during upload to a random string?
- WordPress User Registration/ Sign Up -> Able to take Paid Certification Courses & keep track of Completed Certificates
- Block Root REST API Route using custom &/or iThemes