Nice job recovering your password, however, the exploit probably still exists so you might get hacked again.
Your next step is to find and seal up the security hole. It could be a plugin. It could be a theme.
Download and run the Sucuri plugin to help you figure it out.
Related Posts:
- Security and .htaccess
- What does a security risk in a plugin look like?
- Security issues with WP sites
- Preventing BFA in WordPress without using a plugin
- How To Clean The Malware Infected & Hacked WordPress Websites? [duplicate]
- How to delete Passwrd Protected posts cookies when a user logged out from the site
- Headers Content-Security-Policy CSP Major Issue
- Hack-Proof OR Security in WordPress — is it real?
- Specific way to allow WordPress users to view their current password? And edit it?
- Is there any pre-existing plugin to track and block IPs with suspicious activity on my site?
- Website show Google Ads when we have no Google Ads linked to our website
- WordPress disable direct access of files in WordPress installation path
- How to delete Password Protected posts cookies when a user logged out from the site
- Malware installation during plugin update?
- plugin links not working [closed]
- My WordPress website was hacked [closed]
- Redirect to another page using contact form 7? [closed]
- Remove .htaccess portion upon plugin deactivation?
- Some one is trying to hack my website, Need guidance [closed]
- I should enable automatic updates?
- Can some vulnerabilities in plugins be exploited even when the plugin is inactive?
- Is wp-app.php or wp-apps.php needed for WordPress?
- Security and Must Use Plugins
- Basic password protection without using users and roles
- Is Timthumb still broken? What security measures should be taken?
- Prevent direct access to WordPress plugin assets?
- Completely disabling password reset/recovery
- Is it safe to use admin-ajax.php in the frontend?
- How to protect WordPress from security scanner [closed]
- Edit Permalink Structure For Custom Post Type or Modify .htaccess?
- Troll the hackers by redirecting them
- Custom url rewriting
- Too many login attempts
- How to prevent plugins from sniffing/stealing other plugins’ options?
- Vulnerability Concern From the Plugin or From Not Updating the Plugin?
- Custom API plugin to execute 3rd party API to retrieve data
- How to deal with Slow HTTP POST (slowloris) vulnerability
- Running multiple security plugins
- how do I secure my WP website from hackers? [closed]
- Chrome Dev Tools console says every page in my blog has link to http://maps.google.com [closed]
- Webservice credential storage [duplicate]
- WordPress rewrite rules not working
- Do rewrites added with add_rewrite_rule() persist after plugin deletion?
- Plugin: connect to external database without showing password
- Regarding plugin security
- How do I determine if the user who registered is not spam?
- If I use an alternative login (e.g. CAS or other SSO) plugin, is my site protected from the recent brute force login attempts?
- Is this plugin safe to run?
- Is the Block Bad Queries Plugin Still Relevant?
- WP Insert Post If user refreshes override new post
- 404 errors when updating options in admin dashboard
- Website Captcha Error: The reCAPTCHA wasn’t entered correctly
- Hide plugins and theme from public
- WordPress search shows protected content
- can’t install any wp plugins [duplicate]
- Security of a WordPress Plugin
- Can I disable xml-rpc by setting it to false?
- How can I disable new plugin and theme install, but allow updates?
- Help to Create a Simple Plugin to make a post
- Create Woocommerce account password post-checkout on thank you page
- Add a parameter at the end of the url and prettify
- Validating ajax search
- www redirects to another directory in wordpress
- Content-Security-Policy implementation with WordPress W3Total Cache plugin installed
- Asking help regarding potential malware
- Automatic chage password of pages after some time
- prevent anonymous access to WordPress site (non-admin site)
- wp_set_password() does not work!
- Should I prevent access to .htaccess and wp-config.php files?
- Blocking wp-login in HTACCESS has also blocked password protected pages
- Login/password protected “client page”
- How to allow URL with filename & extension in wordpress?
- Bing/msn bots is heavily requesting random of my website
- How To Use htaccess to Rewrite Link Structure for a Page that is Generated Programatcially
- “Fire Secure” menu item
- WP Migrate DB Pro plugin cannot transfer Media files to remote server
- Login issue in WordPress
- How to make a page both “private” and “password protected”
- Password Protect wp-content?
- Securing a plugin pop-up window
- https rewrite not working for All in one security Brute force > rename login url
- Members-only page, but accessible via sharable link
- URL Rewrite 404
- Create password protected page, no registration
- Cant visualize protected password portfolio elements
- .htaccess file doesn’t work, with hundred tries
- htaccess question and plugins.php
- Help Code Review – I need to write on .htaccess file from theme’s function.php
- How to add subdomain to htaccess
- Redux framework somehow added to my site, can’t locate in plugins
- Being hacked. Is there a list of WordPress security holes I can check against?
- wp_verify_nonce fails always
- Site not displaying correctly when re-directing from root to sub-directory
- How can i see/log all requests coming from a registration form (not from the UI)?
- Write mysql credentials in plugin
- Site is continuously accessing by several IPs
- Validating values using Settings API?
- How To Rewrite WordPress Pages URL Only?
- using .htaccess only for wordpress security no plugins
- SWF in wordpress post