If you do a Google search, you will find many topics on this.
Here are some links:
First read this: http://codex.wordpress.org/FAQ_My_site_was_hacked
Then take a look at these links:
http://ottopress.com/2009/hacked-wordpress-backdoors/
http://wordpress.org/support/topic/268083#post-1065779
http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/
If you have access to your database, login using PHPMyAdmin and change admin username / password, delete users you don’t know and change password for rest.
Then start the process of backing up data and do a clean install.
Note. If you can’t find out how they got access to your site, doing a clean install and putting back data, will still leave whatever hole open.
Also not that backdoors (links / code) could have been added to your posts, so all content must be checked before you import exported data.
Related Posts:
- What’s the effect if this malware if infected your WP?
- Malware on site [closed]
- How to find the backdoor of the hack
- My wordpress site was hacked – is my htaccess file compromised?
- My WordPress Blog sends malicious traffic to other sites [closed]
- Hacked WordPress website, as notified by Google Search Console, what to do? [closed]
- If a WP install is hacked, can it spread to other domains on a server?
- Find and Replace text in the entire table using a MySQL query
- Is it a good idea to rename the “index.php” in “wp-admin” folder to avoid being hacked?
- How to fight this wp-info.php exploit? [closed]
- Prevent Hacking of WordPress Site [closed]
- Suspicious URLs being loaded after hack and restore
- Server hacked: correct contents of wp-uploads directory? [closed]
- Site hacked with malware [closed]
- Copy wordpress website pages and content
- How do I know if my WP Theme is using infamous TimThumb?
- Spam pages hack? [closed]
- Check for malicious code?
- Why would a hacker add this code to each post, and how to do mass cleanup?
- Is the current spate of hacks related to the recent security fix?
- I have removed the malware from our website however, when I tried again to search the word from Google it is still there [closed]
- Have I been hacked? Mysterious code at the top of theme files [closed]
- Strange codes in my wordpress site and my website is running too slow [closed]
- Spam Content Serving from old cached version of site?
- How to solve wordpress redirection (no malware was found)?
- Help determining if the following are legitimate files
- My blog was hacked? WP posting random posts
- Have I been hacked – getting new site setup email for 8 localhost wordpress sites
- Site Hacked – WordPress Divi Site – Cannot find where to fix the issue? [closed]
- malware in wordpress installer on dreamhost. [closed]
- Where I can find a list of WordPress security risks?
- looking for indoxploit hack solution [closed]
- Why functions.php file automatically empty?
- Bruteforce attack from 127.0.0.1?
- WordPress installer attack
- Why wordpress is hitting another url
- Where do hackers usually run their hacking script? [closed]
- Malicious Code in Index.php WordPress [closed]
- WP Site Hacked, Serp Google Spam [closed]
- My site appears to be hacked [closed]
- WordPress Redirect Hack
- Strings of malicious code to look for after a hack
- Hacked/cloaked sitemap [closed]
- Not able to change WordPress admin email. Someone added another admin credentials
- My WordPress Website Redirect to bigbricks.org and other site
- Verifying that I have fully removed a WordPress hack?
- If a hacker changed the blog_charset to UTF-7 does that make WordPress vulnerable to further attacks?
- Scanning Database for malicious Data
- How Attackers write script into my php files?
- Is this a hacking script in function.php?
- Websites defaced by uploading script using theme editor
- How can I find security hole in my wordpress site?
- Has anyone experience w/ WordPress (MultiSite) hidden users (possibly hacked)?
- Restrict access to xmlrpc.php
- How to prevent bot or someone to modify any file automatically?
- How do i disable/disallow and tags in TinyMCE?
- hSite has no css on mobile [closed]
- How to mass delete one line from all posts after site hack
- Strange gibberish JavaScript in Editor – site hacked?
- Security issues with WP sites
- Suspicious Files
- Invisible spam post in backend
- You appear to have already installed WordPress. To reinstall please clear your old database tables first
- sitemap contains weird links and does not contain my pages [closed]
- Malware script in database post table only? [closed]
- New user is assigned 2 roles: customer and superadmin
- Hacked WordPress website /Homepage redirect [closed]
- WordPress Footer Missing After Website Hack
- What is this code in my theme’s footer.php causing chmod permission warnings? [closed]
- What does this code do? (Injected code hacked)
- My WordPress website was hacked [closed]
- Hack-Proof OR Security in WordPress — is it real?
- Some one is trying to hack my website, Need guidance [closed]
- Efficient way to check local WordPress php files and Database for malicious code? [duplicate]
- Is wp-app.php or wp-apps.php needed for WordPress?
- Any known bugs that could cause disappearance of the wp_users table?
- Is there any pre-existing plugin to track and block IPs with suspicious activity on my site?
- On new server, site got hacked, permissions a bit strange? Please help
- Website show Google Ads when we have no Google Ads linked to our website
- Multiple attempted logins originating from the server IP itself?
- Is there a simple way to set wordpress site files back to out of the box?
- Remove hacked code – out of ideas! [closed]
- Username was changed to “admin”
- Am receiving more than thousand mails in single day from ‘[email protected]’ continuously
- How to bulk delete a certain part of all wordpress posts
- WordPress Database Re-installed (Hacked)
- How to log into WordPress via GET/POST
- Verifying that I have fully removed a WordPress hack?
- Subpage is redirecting to spam site
- Open content directory help!
- Hacked site using transient API?
- After being hacked Fatal error: Call to undefined function get_header() in 404.php on line 1
- Could a user account with a stolen password compromised entire WP site?
- how to find the way they hacked my WP site
- How to remove content from hacked pages? [closed]
- How to stop repeated hack on header.php of custom theme? [closed]
- My WordPress site hacked with unwanted popups [closed]
- WordPress Hacks/Defacing [closed]
- Redirected You too Many Times and Homepage Not Loading
- Do not allow the creation of an administrator remotely