{"id":1663,"date":"2026-05-01T14:23:16","date_gmt":"2026-05-01T14:23:16","guid":{"rendered":"https:\/\/www.mogacode.ma\/site-wordpress-pirate-que-faire\/"},"modified":"2026-05-23T14:35:44","modified_gmt":"2026-05-23T14:35:44","slug":"site-wordpress-pirate-que-faire","status":"publish","type":"post","link":"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/","title":{"rendered":"My WordPress site has been hacked: the exact procedure applied to infected sites"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1663\" class=\"elementor elementor-1663 elementor-bc-flex-widget\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-sec_d2a715e elementor-section-stretched elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"sec_d2a715e\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;stretch_section&quot;:&quot;section-stretched&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-col_2cf6ade\" data-id=\"col_2cf6ade\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-htm_f875a2f elementor-widget elementor-widget-html\" data-id=\"htm_f875a2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t\t<style>\n.mg-article *{box-sizing:border-box;margin:0;padding:0}\n.mg-article{font-family:-apple-system,BlinkMacSystemFont,'Inter','Segoe UI',sans-serif;background:#0f0f0f;color:#f0f0f0;line-height:1.6}\n.mg-article .article-header{padding:80px 24px 48px;background:#0f0f0f;max-width:800px;margin:0 auto}\n.mg-article .article-meta{color:#888;font-size:0.875rem;margin-bottom:16px;letter-spacing:0.02em}\n.mg-article .article-meta span{display:inline-block;margin-right:16px}\n.mg-article .article-title{font-size:2.5rem;font-weight:800;line-height:1.2;margin-bottom:24px;color:#f0f0f0}\n.mg-article .article-lead{font-size:1.2rem;color:#ccc;line-height:1.6;border-left:4px solid #FF6B35;padding-left:20px;margin-top:0}\n.mg-article .article-body{max-width:800px;margin:0 auto;padding:48px 24px}\n.mg-article .article-body h2{font-size:1.75rem;font-weight:700;margin:48px 0 16px;color:#f0f0f0}\n.mg-article .article-body h3{font-size:1.3rem;font-weight:600;margin:32px 0 12px;color:#FF6B35}\n.mg-article .article-body p{margin-bottom:20px;line-height:1.8;color:#d0d0d0}\n.mg-article .article-body ul,.mg-article .article-body ol{padding-left:24px;margin-bottom:20px}\n.mg-article .article-body li{margin-bottom:8px;line-height:1.7;color:#d0d0d0}\n.mg-article .article-body blockquote{border-left:4px solid #FF6B35;padding:16px 24px;background:#1a1a1a;margin:32px 0;font-style:italic;color:#ccc;border-radius:0 8px 8px 0}\n.mg-article .highlight-box{background:#1a1a1a;border:1px solid #2a2a2a;border-radius:8px;padding:24px;margin:32px 0}\n.mg-article .highlight-box h3{margin-top:0;color:#FF6B35}\n.mg-article .code-block{background:#111;border:1px solid #2a2a2a;border-radius:8px;padding:20px;font-family:monospace;font-size:0.875rem;color:#a8ff78;overflow-x:auto;margin:24px 0;white-space:pre}\n.mg-article .inline-cta{background:linear-gradient(135deg,#FF6B35,#e85a20);border-radius:8px;padding:32px;text-align:center;margin:48px 0}\n.mg-article .inline-cta h3{color:#fff;margin-bottom:12px;font-size:1.5rem;margin-top:0}\n.mg-article .inline-cta p{color:rgba(255,255,255,0.85);margin-bottom:24px}\n.mg-article .btn-white{display:inline-block;background:#fff;color:#FF6B35;font-weight:700;padding:14px 28px;border-radius:6px;text-decoration:none;font-size:1rem}\n.mg-article .author-box{display:flex;gap:16px;align-items:center;background:#1a1a1a;border-radius:8px;padding:24px;margin:48px 0;border:1px solid #2a2a2a}\n.mg-article .author-avatar{width:64px;height:64px;border-radius:50%;background:#FF6B35;display:flex;align-items:center;justify-content:center;font-size:1.5rem;font-weight:800;color:#fff;flex-shrink:0}\n.mg-article .author-info h4{margin:0 0 4px;font-size:1rem;font-weight:600;color:#f0f0f0}\n.mg-article .author-info p{margin:0;color:#888;font-size:0.875rem}\n.mg-article .article-cta-bottom{background:#141414;padding:64px 24px;text-align:center;border-top:1px solid #2a2a2a}\n.mg-article .article-cta-bottom h2{font-size:1.75rem;font-weight:700;margin-bottom:16px;color:#f0f0f0}\n.mg-article .article-cta-bottom p{color:#888;max-width:560px;margin:0 auto 28px;line-height:1.7}\n.mg-article .btn-orange{display:inline-block;background:#FF6B35;color:#fff;font-weight:700;padding:14px 28px;border-radius:6px;text-decoration:none;font-size:1rem}\n.mg-article .danger-badge{display:inline-block;background:#ff3b3b;color:#fff;font-size:0.75rem;font-weight:700;padding:4px 10px;border-radius:4px;text-transform:uppercase;letter-spacing:0.05em;margin-bottom:8px}\n.mg-article .step-number{display:inline-flex;align-items:center;justify-content:center;width:32px;height:32px;border-radius:50%;background:#FF6B35;color:#fff;font-weight:800;font-size:0.875rem;flex-shrink:0;margin-right:12px}\n.mg-article .step-row{display:flex;align-items:flex-start;gap:0;margin-bottom:16px}\n.mg-article .step-content{flex:1}\n.mg-article .step-content strong{color:#f0f0f0}\n<\/style>\n\n<div class=\"mg-article\">\n  <div class=\"article-header\">\n    <div class=\"article-meta\">\n      <span>WordPress Security<\/span>\n      <span>May 1, 2026<\/span>\n      <span>Reading time: 9 min<\/span>\n    <\/div>\n    <h1 class=\"article-title\">My WordPress site has been hacked: what should I do? (Complete Guide 2026)<\/h1>\n    <p class=\"article-lead\">Your site is displaying spam, redirecting to unknown pages, or your hosting provider has suspended it. Don&#039;t panic. Here&#039;s the exact procedure to diagnose, clean, and secure a compromised WordPress site\u2014the one we use ourselves at MogaCode.<\/p>\n  <\/div>\n\n  <div class=\"article-body\">\n\n    <h2>How can you tell if your site has really been hacked?<\/h2>\n    <p>Before reinstalling everything, identify the symptoms. A slow or misconfigured website can resemble an infected site. Here are the telltale signs:<\/p>\n\n    <ul>\n      <li><strong>Redirects to unknown websites<\/strong> \u2014 Upon clicking, your visitors land on phishing pages or fake antivirus software.<\/li>\n      <li><strong>Google Search Console displays &quot;Deceptive site&quot;\"<\/strong> \u2014 Google has detected malicious content and blacklisted your domain<\/li>\n      <li><strong>Your hosting provider has suspended the account<\/strong> \u2014 Infomaniak or OVH send an alert with suspicious file names<\/li>\n      <li><strong>New administrator users have appeared.<\/strong> in WordPress without you having created them<\/li>\n      <li><strong>Unknown PHP files are lying around<\/strong> in wp-content\/uploads\/, wp-includes\/ or at the root<\/li>\n      <li><strong>The HTML source contains hidden links.<\/strong> to third-party sites (at the bottom of the page, in display:none style tags)<\/li>\n    <\/ul>\n\n    <blockquote>\n      \"&quot;In April 2026, 21 MogaCode customer sites were infected overnight via nullified plugins. Patrick Rary diagnosed and cleaned everything up in less than 12 hours. The attack vector: a unique backdoor encoded in each hacked plugin.&quot;\"\n    <\/blockquote>\n\n    <h2>Step 1 \u2014 Isolate and diagnose<\/h2>\n    <p>Do not touch anything until you have a clear picture of the infection. Acting blindly risks concealing traces and leaving active backdoors.<\/p>\n\n    <div class=\"step-row\">\n      <span class=\"step-number\">1<\/span>\n      <div class=\"step-content\"><strong>Put the site into maintenance mode<\/strong> \u2014 activate a maintenance plugin or add a .htaccess file to block public access during cleanup.<\/div>\n    <\/div>\n    <div class=\"step-row\">\n      <span class=\"step-number\">2<\/span>\n      <div class=\"step-content\"><strong>Export a complete dump<\/strong> \u2014 Even if infected, keep a copy. Don&#039;t delete anything without a backup.<\/div>\n    <\/div>\n    <div class=\"step-row\">\n      <span class=\"step-number\">3<\/span>\n      <div class=\"step-content\"><strong>Run a scan with Wordfence or MalCare<\/strong> \u2014 These plugins compare your WordPress core files with the official originals and flag each difference.<\/div>\n    <\/div>\n    <div class=\"step-row\">\n      <span class=\"step-number\">4<\/span>\n      <div class=\"step-content\"><strong>Search for recently modified files<\/strong> \u2014 via SSH: <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">find . -name &quot;*.php&quot; -newer wp-config.php -not -path &quot;*\/uploads\/*&quot;\"<\/code><\/div>\n    <\/div>\n\n    <h2>Step 2 \u2014 DIY Cleanup (if you have SSH access)<\/h2>\n\n    <h3>Remove malicious files<\/h3>\n    <p>Backdoors are often hidden in files with innocuous names: <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">wp-includes\/class-wp-clean.php<\/code>, <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">wp-content\/uploads\/2025\/cache.php<\/code> or PHP files in wp-content\/uploads (uploads should never contain PHP).<\/p>\n\n    <div class=\"code-block\">find wp-content\/uploads -name &quot;*.php&quot; -delete find wp-includes -name &quot;*.php&quot; | xargs grep -l &quot;eval(base64_decode&quot; | xargs rm grep -r &quot;cAT3VWynuiL7CRgr&quot; . --include=&quot;*.php&quot; -l<\/div>\n\n    <h3>Reinstall the core files<\/h3>\n    <p>Never trust the core files of an infected site. Download a fresh WordPress installation and replace all core files (everything except wp-content\/ and wp-config.php).<\/p>\n\n    <h3>Change all passwords<\/h3>\n    <ul>\n      <li>WordPress password for each administrator<\/li>\n      <li>Database password (in wp-config.php)<\/li>\n      <li>FTP\/SFTP password for the hosting<\/li>\n      <li>WordPress security keys (AUTH_KEY, SECURE_AUTH_KEY, etc.) \u2014 regenerate them at api.wordpress.org\/secret-key\/1.1\/salt\/<\/li>\n    <\/ul>\n\n    <div class=\"highlight-box\">\n      <h3>When should you call a professional?<\/h3>\n      <p style=\"color:#ccc;margin-bottom:12px\">If you encounter any of these issues, don&#039;t waste any more time trying to clean it yourself:<\/p>\n      <ul>\n        <li>The infection recurs after cleaning (persistent backdoor or compromised admin account)<\/li>\n        <li>Google has blacklisted your domain (partial or total deindexing)<\/li>\n        <li>You do not have SSH access or the file permissions have been changed.<\/li>\n        <li>You have an e-commerce website with customer data (GDPR risk)<\/li>\n        <li>Your hosting provider refuses to reactivate the account without validation.<\/li>\n      <\/ul>\n    <\/div>\n\n    <div class=\"inline-cta\">\n      <h3>Is your website infected?<\/h3>\n      <p>MogaCode handles complete cleanup, hardening, and the implementation of active monitoring. Rapid response \u2014 typically within 24 hours.<\/p>\n      <a href=\"https:\/\/www.mogacode.ma\/en\/contact\/\" class=\"btn-white\">Request an intervention<\/a>\n    <\/div>\n\n    <h2>Step 3 \u2014 Post-cleaning hardening<\/h2>\n    <p>A cleaned but unhardened site will be reinfected. That&#039;s a certainty. Here are the essential measures:<\/p>\n\n    <h3>Secure wp-config.php<\/h3>\n    <div class=\"code-block\"># In .htaccess, block direct access to wp-config.php order allow,deny deny from all # Move wp-config.php one level above the web root. # WordPress will find it automatically.<\/div>\n\n    <h3>File permissions are correct.<\/h3>\n    <div class=\"code-block\">find . -type d -exec chmod 755 {} \\; find . -type f -exec chmod 644 {} \\; chmod 600 wp-config.php<\/div>\n\n    <h3>Enable two-factor authentication<\/h3>\n    <p>The &quot;WP 2FA&quot; or &quot;Google Authenticator&quot; plugin for WordPress adds a TOTP (Token of Validation) to the login page. This is the most effective measure against brute-force attacks on \/wp-admin.<\/p>\n\n    <h3>Implementing a WAF<\/h3>\n    <p>A Web Application Firewall (Wordfence Premium, Cloudflare WAF) blocks attacks before they even reach WordPress. On our Infomaniak servers, we systematically activate Wordfence with a geo-blocking rule targeting countries with high automated scanning activity.<\/p>\n\n    <h3>Never use useless plugins<\/h3>\n    <p>This is the most painful lesson. In April 2026, 21 of our clients&#039; websites were infected overnight via pirated versions of Elementor Pro, Ultimate Elementor, and RevSlider. These plugins all contained the same signature: <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">cAT3VWynuiL7CRgr<\/code>. A clean, discreet backdoor, already in place for weeks before activation.<\/p>\n\n    <div class=\"highlight-box\">\n      <h3>WordPress Hardening Checklist<\/h3>\n      <ul>\n        <li>WordPress updates, themes and plugins \u2014 without exception<\/li>\n        <li>Removal of inactive themes and plugins<\/li>\n        <li>Limitation of login attempts (Limit Login Attempts)<\/li>\n        <li>2FA authentication on all admin accounts<\/li>\n        <li>Weekly automatic security scan (Wordfence)<\/li>\n        <li>Automatic daily off-server backups<\/li>\n        <li>HTTPS enabled with HSTS<\/li>\n        <li>HTTP security headers (X-Frame-Options, CSP, X-Content-Type-Options)<\/li>\n        <li>Hiding the WordPress version (in the meta tags and RSS feed)<\/li>\n        <li>Disable xmlrpc.php if not used<\/li>\n      <\/ul>\n    <\/div>\n\n    <div class=\"author-box\">\n      <div class=\"author-avatar\">P<\/div>\n      <div class=\"author-info\">\n        <h4>Patrick Rary<\/h4>\n        <p>Fondateur MogaCode \u2014 Ing\u00e9nieur informaticien, 30 ans d'experience IT. A nettoye plus de 80 sites WordPress infectes depuis 2020.<\/p>\n      <\/div>\n    <\/div>\n\n  <\/div>\n\n  <div class=\"article-cta-bottom\">\n    <h2>MogaCode Care \u2014 Maintenance that prevents<\/h2>\n    <p>Updates, backups, 24\/7 monitoring, active WAF. Your WordPress site is monitored without you having to think about it.<\/p>\n    <a href=\"https:\/\/www.mogacode.ma\/en\/sites-wordpress\/\" class=\"btn-orange\">Discover MogaCode Care<\/a>\n  <\/div>\n<\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Sympt\u00f4mes, diagnostic, nettoyage, durcissement, restauration de la visibilit\u00e9 Google. La proc\u00e9dure compl\u00e8te que MogaCode applique sur les sites compromis.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,16],"tags":[],"class_list":["post-1663","post","type-post","status-publish","format-standard","hentry","category-s-curit-wordpress","category-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v28.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Site WordPress Pirat\u00e9 \u2014 Que Faire ? Guide 2026 | MogaCode<\/title>\n<meta name=\"description\" content=\"Sympt\u00f4mes d&#039;un site WordPress compromis, premi\u00e8re intervention, nettoyage, durcissement. La proc\u00e9dure que MogaCode applique sur les sites infect\u00e9s.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mon site WordPress est pirat\u00e9 : la proc\u00e9dure exacte qu&#039;on applique sur les sites infect\u00e9s\" \/>\n<meta property=\"og:description\" content=\"Sympt\u00f4mes d&#039;un site WordPress compromis, premi\u00e8re intervention, nettoyage, durcissement. La proc\u00e9dure que MogaCode applique sur les sites infect\u00e9s.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/\" \/>\n<meta property=\"og:site_name\" content=\"Mogacode\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-01T14:23:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-23T14:35:44+00:00\" \/>\n<meta name=\"author\" content=\"Patrick\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@mogacode\" \/>\n<meta name=\"twitter:site\" content=\"@mogacode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Patrick\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Hacked WordPress Site \u2014 What to Do? 2026 Guide | MogaCode","description":"Sympt\u00f4mes d'un site WordPress compromis, premi\u00e8re intervention, nettoyage, durcissement. La proc\u00e9dure que MogaCode applique sur les sites infect\u00e9s.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/","og_locale":"en_US","og_type":"article","og_title":"Mon site WordPress est pirat\u00e9 : la proc\u00e9dure exacte qu'on applique sur les sites infect\u00e9s","og_description":"Sympt\u00f4mes d'un site WordPress compromis, premi\u00e8re intervention, nettoyage, durcissement. La proc\u00e9dure que MogaCode applique sur les sites infect\u00e9s.","og_url":"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/","og_site_name":"Mogacode","article_publisher":"https:\/\/www.facebook.com\/mogacode","article_author":"https:\/\/www.facebook.com\/mogacode","article_published_time":"2026-05-01T14:23:16+00:00","article_modified_time":"2026-05-23T14:35:44+00:00","author":"Patrick","twitter_card":"summary_large_image","twitter_creator":"@mogacode","twitter_site":"@mogacode","twitter_misc":{"Written by":"Patrick","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[]}},"_links":{"self":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/comments?post=1663"}],"version-history":[{"count":10,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1663\/revisions"}],"predecessor-version":[{"id":1790,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1663\/revisions\/1790"}],"wp:attachment":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/media?parent=1663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/categories?post=1663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/tags?post=1663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}