Nice job recovering your password, however, the exploit probably still exists so you might get hacked again.
Your next step is to find and seal up the security hole. It could be a plugin. It could be a theme.
Download and run the Sucuri plugin to help you figure it out.
Related Posts:
- Security and .htaccess
- What does a security risk in a plugin look like?
- Security issues with WP sites
- Preventing BFA in WordPress without using a plugin
- How To Clean The Malware Infected & Hacked WordPress Websites? [duplicate]
- How to delete Passwrd Protected posts cookies when a user logged out from the site
- Headers Content-Security-Policy CSP Major Issue
- Hack-Proof OR Security in WordPress — is it real?
- Specific way to allow WordPress users to view their current password? And edit it?
- Is there any pre-existing plugin to track and block IPs with suspicious activity on my site?
- Website show Google Ads when we have no Google Ads linked to our website
- WordPress disable direct access of files in WordPress installation path
- How to delete Password Protected posts cookies when a user logged out from the site
- What security concerns should I have when setting FS_METHOD to “direct” in wp-config?
- What Are Security Best Practices for WordPress Plugins and Themes? [closed]
- What are the common security flaws I need to look for? [closed]
- Why “Contact Form 7” doesn’t update PHPmailer library?
- How to stop wordpress from changing default .htaccess permissions to 444
- How to make media upload private? [duplicate]
- Does WordPress contain “default” anti-SQL injection code that responds with a 404 error?
- WordPress Capabilities: edit_user vs edit_users
- Add new password rule to Ultimate Member register form
- login to wordpress with Get variables instead of Post
- Why am I sometimes getting a 404 error when I try to update a page with Elementor?
- Should I use RIPS tool to test my themes and plugins?
- Is it possible to block subscriber users to changing its password?
- Problem protecting a page with a password
- Why users disable the WordPress update?
- How many security plugins are too many? [closed]
- Will WordPress username displayed somewhere in the site?
- Upgrading WordPress 4.0 asks for FTP password
- Is revealing just the AUTH_KEY a security issue?
- How Restrict access to admin dashboard by specific static ip?
- Protecting against malicious code in WordPress plugin updates
- Is there any good tutorial to write custom login, registration and password recovery forms? [closed]
- htaccess and wordpress config files are regularly over written
- Why Better WP security plugin returns 418 I’m a Teapot “error”?
- How to limit WordPress pages during updates?
- WordPress redirect all 404 pages to the Homepage
- rms_unique_wp_mu_pl_fl_nm.php
- How can I serve a text file at a custom URL
- Security checking in meta_box save is reluctant?
- The safest way to automate WordPress backups
- wp_create_nonce function doesn’t work inside a plugin?
- Does WordPress validate inputs to all functions? (such as get_user_meta and insert_user_meta)
- Nonce failing on form submission
- Reoccurring 404 Errors on all subpages
- Is there a directory my plugin can write files to that cannot be viewed via the browser/url?
- My WordPress website was hacked [closed]
- Some one is trying to hack my website, Need guidance [closed]
- I should enable automatic updates?
- Can some vulnerabilities in plugins be exploited even when the plugin is inactive?
- Prevent direct access to WordPress plugin assets?
- Completely disabling password reset/recovery
- Too many login attempts
- Custom API plugin to execute 3rd party API to retrieve data
- How to deal with Slow HTTP POST (slowloris) vulnerability
- Running multiple security plugins
- how do I secure my WP website from hackers? [closed]
- Chrome Dev Tools console says every page in my blog has link to [closed]
- Webservice credential storage [duplicate]
- WordPress rewrite rules not working
- Regarding plugin security
- Is this plugin safe to run?
- Is the Block Bad Queries Plugin Still Relevant?
- Hide plugins and theme from public
- Security of a WordPress Plugin
- Create Woocommerce account password post-checkout on thank you page
- Automatic chage password of pages after some time
- prevent anonymous access to WordPress site (non-admin site)
- wp_set_password() does not work!
- Blocking wp-login in HTACCESS has also blocked password protected pages
- How to allow URL with filename & extension in wordpress?
- Bing/msn bots is heavily requesting random of my website
- How To Use htaccess to Rewrite Link Structure for a Page that is Generated Programatcially
- WP Migrate DB Pro plugin cannot transfer Media files to remote server
- Password Protect wp-content?
- Securing a plugin pop-up window
- URL Rewrite 404
- .htaccess file doesn’t work, with hundred tries
- Help Code Review – I need to write on .htaccess file from theme’s function.php
- How to add subdomain to htaccess
- How can i see/log all requests coming from a registration form (not from the UI)?
- Write mysql credentials in plugin
- Site is continuously accessing by several IPs
- using .htaccess only for wordpress security no plugins
- SWF in wordpress post
- Apache rewrite rules and wordpress problem
- Unwanted Links and Spam WordPress Pages and Posts
- incorrect path of plugin dir on network
- Alter the reset password link
- Could a user account with a stolen password compromised entire WP site?
- File permissions for wp-minify plugin
- What is the recommended way to be notified of security updates to my plugins? [closed]
- Is my WP site being hacked?
- Please Check this ‘.htaccess’ File
- Allow direct access to files/folders within WordPress to replace wp-admin
- WordPress website is redirecting on some different shopping page
- WordPress User Registration/ Sign Up -> Able to take Paid Certification Courses & keep track of Completed Certificates
- Block Root REST API Route using custom &/or iThemes