Your website is infected by Malware.
Hackers are using your WordPress website for ‘spamvertising.’
This causes an insane traffic spike. Spam emails are sent from your server with links to existing or new pages that are created by the hacker.
Spamvertising can vandalize blogs, websites, forums, and comment sections with hyperlinks to get a higher search engine ranking for the hacker’s website.
In some cases, an attacker will decide to use your web server as a platform to launch attacks on other websites. This is relatively rare based on Wordfence respondents, who only reported this happening 0.7% of the time. (and it’s your case as I see)
The first thing to do is to install GOTMLS free plugin and scan your website, then check your database for admin users added by malware.
Please attach a screenshot of GOTMLS scan so I can tell you what you need to do exactly.
Related Posts:
- What’s the effect if this malware if infected your WP?
- Malware on site [closed]
- How to find the backdoor of the hack
- My wordpress site was hacked – is my htaccess file compromised?
- Hacked WordPress website, as notified by Google Search Console, what to do? [closed]
- How was my WP site hacked [closed]
- Unfamiliar query string in Google Search Console URL not found
- If a WP install is hacked, can it spread to other domains on a server?
- Find and Replace text in the entire table using a MySQL query
- Is it a good idea to rename the “index.php” in “wp-admin” folder to avoid being hacked?
- How to fight this wp-info.php exploit? [closed]
- Prevent Hacking of WordPress Site [closed]
- Suspicious URLs being loaded after hack and restore
- Server hacked: correct contents of wp-uploads directory? [closed]
- Site hacked with malware [closed]
- Copy wordpress website pages and content
- How do I know if my WP Theme is using infamous TimThumb?
- Spam pages hack? [closed]
- Check for malicious code?
- Why would a hacker add this code to each post, and how to do mass cleanup?
- Is the current spate of hacks related to the recent security fix?
- I have removed the malware from our website however, when I tried again to search the word from Google it is still there [closed]
- Have I been hacked? Mysterious code at the top of theme files [closed]
- Strange codes in my wordpress site and my website is running too slow [closed]
- Spam Content Serving from old cached version of site?
- How to solve wordpress redirection (no malware was found)?
- Help determining if the following are legitimate files
- My blog was hacked? WP posting random posts
- Have I been hacked – getting new site setup email for 8 localhost wordpress sites
- Site Hacked – WordPress Divi Site – Cannot find where to fix the issue? [closed]
- malware in wordpress installer on dreamhost. [closed]
- Where I can find a list of WordPress security risks?
- looking for indoxploit hack solution [closed]
- Why functions.php file automatically empty?
- Bruteforce attack from 127.0.0.1?
- WordPress installer attack
- Why wordpress is hitting another url
- Where do hackers usually run their hacking script? [closed]
- Malicious Code in Index.php WordPress [closed]
- WP Site Hacked, Serp Google Spam [closed]
- My site appears to be hacked [closed]
- WordPress Redirect Hack
- Strings of malicious code to look for after a hack
- Hacked/cloaked sitemap [closed]
- Verifying that I have fully removed a WordPress hack?
- If a hacker changed the blog_charset to UTF-7 does that make WordPress vulnerable to further attacks?
- How to pass on Google Adwords gclid variable to other pages
- How Attackers write script into my php files?
- Is this a hacking script in function.php?
- Correct way to hide pseudo pages from being shown?
- Google Places API With ACF [closed]
- Restrict access to xmlrpc.php
- How to stop a 500 error on the WordPress theme folder
- How to implement Google reCaptcha without installing a plugin?
- How to mass delete one line from all posts after site hack
- Security issues with WP sites
- WordPress categories being called “archives” in google links. How to remove?
- media sideload image and Google Content
- Increased CPU load due to admin-ajax.php spam
- For using google api is it necessary to install the google client libraries for using Oauth 2 in wordpress installation?
- Block google maps from loading until user agrees to cookies with Elementor
- Google Adwords Tracking Code causing too many redirects error
- WordPress Footer Missing After Website Hack
- What is this code in my theme’s footer.php causing chmod permission warnings? [closed]
- Restrict access to content in conjunction with facebook connect & google login
- Excerpt formatting for Google News Feed [closed]
- What does this code do? (Injected code hacked)
- My WordPress website was hacked [closed]
- Hack-Proof OR Security in WordPress — is it real?
- Fall Back Google CDN in JavaScript
- Is wp-app.php or wp-apps.php needed for WordPress?
- Automatically post to Google+ on new post
- Remove Query String from Google jQuery
- Prioritize visible content – Page speed issue on Google insights
- How to remove Google Analyticator in WordPress site?
- Any known bugs that could cause disappearance of the wp_users table?
- Is there any pre-existing plugin to track and block IPs with suspicious activity on my site?
- On new server, site got hacked, permissions a bit strange? Please help
- Multiple attempted logins originating from the server IP itself?
- Stop wordpress from requesting external jquery from googleapi
- Is there a simple way to set wordpress site files back to out of the box?
- Pinging or sitemap plugin: which practice is better
- Username was changed to “admin”
- How can I receive uploaded attach file as a Google drive link [closed]
- How to add height and width to images on a page(using WP Bakery) to improve Google’s CLS score?
- How to fetch csv file and show in shortcode
- How to force one script to load before google tag manager script
- Am receiving more than thousand mails in single day from ‘[email protected]’ continuously
- Verifying that I have fully removed a WordPress hack?
- WordPress generates weird permalinks
- Display posts on a map
- WordPress URL question
- Could a user account with a stolen password compromised entire WP site?
- Google adsense stats plugin? [closed]
- How can I add a google play badge to my header and footer?
- How to remove content from hacked pages? [closed]
- My WordPress site hacked with unwanted popups [closed]
- Google is unable to crawl Robots.txt file of my website and please help me
- WordPress Hacks/Defacing [closed]
- How to improve WordPress website SEO and traffic, and or fix SEO issues