{"id":1663,"date":"2026-05-01T14:23:16","date_gmt":"2026-05-01T14:23:16","guid":{"rendered":"https:\/\/www.mogacode.ma\/site-wordpress-pirate-que-faire\/"},"modified":"2026-05-23T14:35:44","modified_gmt":"2026-05-23T14:35:44","slug":"site-wordpress-pirate-que-faire","status":"publish","type":"post","link":"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/","title":{"rendered":"My WordPress site has been hacked: the exact procedure applied to infected sites"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1663\" class=\"elementor elementor-1663 elementor-bc-flex-widget\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-sec_d2a715e elementor-section-stretched elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"sec_d2a715e\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;stretch_section&quot;:&quot;section-stretched&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-col_2cf6ade\" data-id=\"col_2cf6ade\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-htm_f875a2f elementor-widget elementor-widget-html\" data-id=\"htm_f875a2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t\t<style>\n.mg-article *{box-sizing:border-box;margin:0;padding:0}\n.mg-article{font-family:-apple-system,BlinkMacSystemFont,'Inter','Segoe UI',sans-serif;background:#0f0f0f;color:#f0f0f0;line-height:1.6}\n.mg-article .article-header{padding:80px 24px 48px;background:#0f0f0f;max-width:800px;margin:0 auto}\n.mg-article .article-meta{color:#888;font-size:0.875rem;margin-bottom:16px;letter-spacing:0.02em}\n.mg-article .article-meta span{display:inline-block;margin-right:16px}\n.mg-article .article-title{font-size:2.5rem;font-weight:800;line-height:1.2;margin-bottom:24px;color:#f0f0f0}\n.mg-article .article-lead{font-size:1.2rem;color:#ccc;line-height:1.6;border-left:4px solid #FF6B35;padding-left:20px;margin-top:0}\n.mg-article .article-body{max-width:800px;margin:0 auto;padding:48px 24px}\n.mg-article .article-body h2{font-size:1.75rem;font-weight:700;margin:48px 0 16px;color:#f0f0f0}\n.mg-article .article-body h3{font-size:1.3rem;font-weight:600;margin:32px 0 12px;color:#FF6B35}\n.mg-article .article-body p{margin-bottom:20px;line-height:1.8;color:#d0d0d0}\n.mg-article .article-body ul,.mg-article .article-body ol{padding-left:24px;margin-bottom:20px}\n.mg-article .article-body li{margin-bottom:8px;line-height:1.7;color:#d0d0d0}\n.mg-article .article-body blockquote{border-left:4px solid #FF6B35;padding:16px 24px;background:#1a1a1a;margin:32px 0;font-style:italic;color:#ccc;border-radius:0 8px 8px 0}\n.mg-article .highlight-box{background:#1a1a1a;border:1px solid #2a2a2a;border-radius:8px;padding:24px;margin:32px 0}\n.mg-article .highlight-box h3{margin-top:0;color:#FF6B35}\n.mg-article .code-block{background:#111;border:1px solid #2a2a2a;border-radius:8px;padding:20px;font-family:monospace;font-size:0.875rem;color:#a8ff78;overflow-x:auto;margin:24px 0;white-space:pre}\n.mg-article .inline-cta{background:linear-gradient(135deg,#FF6B35,#e85a20);border-radius:8px;padding:32px;text-align:center;margin:48px 0}\n.mg-article .inline-cta h3{color:#fff;margin-bottom:12px;font-size:1.5rem;margin-top:0}\n.mg-article .inline-cta p{color:rgba(255,255,255,0.85);margin-bottom:24px}\n.mg-article .btn-white{display:inline-block;background:#fff;color:#FF6B35;font-weight:700;padding:14px 28px;border-radius:6px;text-decoration:none;font-size:1rem}\n.mg-article .author-box{display:flex;gap:16px;align-items:center;background:#1a1a1a;border-radius:8px;padding:24px;margin:48px 0;border:1px solid #2a2a2a}\n.mg-article .author-avatar{width:64px;height:64px;border-radius:50%;background:#FF6B35;display:flex;align-items:center;justify-content:center;font-size:1.5rem;font-weight:800;color:#fff;flex-shrink:0}\n.mg-article .author-info h4{margin:0 0 4px;font-size:1rem;font-weight:600;color:#f0f0f0}\n.mg-article .author-info p{margin:0;color:#888;font-size:0.875rem}\n.mg-article .article-cta-bottom{background:#141414;padding:64px 24px;text-align:center;border-top:1px solid #2a2a2a}\n.mg-article .article-cta-bottom h2{font-size:1.75rem;font-weight:700;margin-bottom:16px;color:#f0f0f0}\n.mg-article .article-cta-bottom p{color:#888;max-width:560px;margin:0 auto 28px;line-height:1.7}\n.mg-article .btn-orange{display:inline-block;background:#FF6B35;color:#fff;font-weight:700;padding:14px 28px;border-radius:6px;text-decoration:none;font-size:1rem}\n.mg-article .danger-badge{display:inline-block;background:#ff3b3b;color:#fff;font-size:0.75rem;font-weight:700;padding:4px 10px;border-radius:4px;text-transform:uppercase;letter-spacing:0.05em;margin-bottom:8px}\n.mg-article .step-number{display:inline-flex;align-items:center;justify-content:center;width:32px;height:32px;border-radius:50%;background:#FF6B35;color:#fff;font-weight:800;font-size:0.875rem;flex-shrink:0;margin-right:12px}\n.mg-article .step-row{display:flex;align-items:flex-start;gap:0;margin-bottom:16px}\n.mg-article .step-content{flex:1}\n.mg-article .step-content strong{color:#f0f0f0}\n<\/style>\n\n<div class=\"mg-article\">\n  <div class=\"article-header\">\n    <div class=\"article-meta\">\n      <span>WordPress Security<\/span>\n      <span>May 1, 2026<\/span>\n      <span>Reading time: 9 min<\/span>\n    <\/div>\n    <h1 class=\"article-title\">My WordPress site has been hacked: what should I do? (Complete Guide 2026)<\/h1>\n    <p class=\"article-lead\">Votre site affiche du spam, redirige vers des pages inconnues ou votre h\u00e9bergeur l'a suspendu. Pas de panique. Voici la proc\u00e9dure exacte pour diagnostiquer, nettoyer et s\u00e9curiser un WordPress compromis, celle que nous appliquons nous-m\u00eames chez MogaCode.<\/p>\n  <\/div>\n\n  <div class=\"article-body\">\n\n    <h2>How can you tell if your site has really been hacked?<\/h2>\n    <p>Before reinstalling everything, identify the symptoms. A slow or misconfigured website can resemble an infected site. Here are the telltale signs:<\/p>\n\n    <ul>\n      <li><strong>Redirects to unknown websites<\/strong>, au clic, vos visiteurs atterrissent sur des pages de phishing ou de faux antivirus<\/li>\n      <li><strong>Google Search Console displays &quot;Deceptive site&quot;\"<\/strong>, Google a d\u00e9tect\u00e9 du contenu malveillant et blacklist\u00e9 votre domaine<\/li>\n      <li><strong>Your hosting provider has suspended the account<\/strong>, Infomaniak ou OVH envoient une alerte avec des noms de fichiers suspects<\/li>\n      <li><strong>New administrator users have appeared.<\/strong> in WordPress without you having created them<\/li>\n      <li><strong>Unknown PHP files are lying around<\/strong> in wp-content\/uploads\/, wp-includes\/ or at the root<\/li>\n      <li><strong>The HTML source contains hidden links.<\/strong> to third-party sites (at the bottom of the page, in display:none style tags)<\/li>\n    <\/ul>\n\n    <blockquote>\n      \"&quot;In April 2026, 21 MogaCode customer sites were infected overnight via nullified plugins. Patrick Rary diagnosed and cleaned everything up in less than 12 hours. The attack vector: a unique backdoor encoded in each hacked plugin.&quot;\"\n    <\/blockquote>\n\n    <h2>Etape 1, Isoler et diagnostiquer<\/h2>\n    <p>Do not touch anything until you have a clear picture of the infection. Acting blindly risks concealing traces and leaving active backdoors.<\/p>\n\n    <div class=\"step-row\">\n      <span class=\"step-number\">1<\/span>\n      <div class=\"step-content\"><strong>Put the site into maintenance mode<\/strong>, activez un plugin de maintenance ou ajoutez un .htaccess pour bloquer l'acc\u00e8s public pendant le nettoyage.<\/div>\n    <\/div>\n    <div class=\"step-row\">\n      <span class=\"step-number\">2<\/span>\n      <div class=\"step-content\"><strong>Export a complete dump<\/strong>, m\u00eame infect\u00e9, gardez une copie. On ne supprime rien sans backup.<\/div>\n    <\/div>\n    <div class=\"step-row\">\n      <span class=\"step-number\">3<\/span>\n      <div class=\"step-content\"><strong>Run a scan with Wordfence or MalCare<\/strong>, ces plugins comparent vos fichiers core WordPress avec les originaux officiels et signalent chaque diff\u00e9rence.<\/div>\n    <\/div>\n    <div class=\"step-row\">\n      <span class=\"step-number\">4<\/span>\n      <div class=\"step-content\"><strong>Search for recently modified files<\/strong>, via SSH : <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">find . -name &quot;*.php&quot; -newer wp-config.php -not -path &quot;*\/uploads\/*&quot;\"<\/code><\/div>\n    <\/div>\n\n    <h2>Etape 2, Nettoyage DIY (si vous avez les acc\u00e8s SSH)<\/h2>\n\n    <h3>Remove malicious files<\/h3>\n    <p>Backdoors are often hidden in files with innocuous names: <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">wp-includes\/class-wp-clean.php<\/code>, <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">wp-content\/uploads\/2025\/cache.php<\/code> or PHP files in wp-content\/uploads (uploads should never contain PHP).<\/p>\n\n    <div class=\"code-block\">find wp-content\/uploads -name &quot;*.php&quot; -delete find wp-includes -name &quot;*.php&quot; | xargs grep -l &quot;eval(base64_decode&quot; | xargs rm grep -r &quot;cAT3VWynuiL7CRgr&quot; . --include=&quot;*.php&quot; -l<\/div>\n\n    <h3>Reinstall the core files<\/h3>\n    <p>Never trust the core files of an infected site. Download a fresh WordPress installation and replace all core files (everything except wp-content\/ and wp-config.php).<\/p>\n\n    <h3>Change all passwords<\/h3>\n    <ul>\n      <li>WordPress password for each administrator<\/li>\n      <li>Database password (in wp-config.php)<\/li>\n      <li>FTP\/SFTP password for the hosting<\/li>\n      <li>Les security keys WordPress (AUTH_KEY, SECURE_AUTH_KEY, etc.), reg\u00e9n\u00e9rez-les sur api.wordpress.org\/secret-key\/1.1\/salt\/<\/li>\n    <\/ul>\n\n    <div class=\"highlight-box\">\n      <h3>When should you call a professional?<\/h3>\n      <p style=\"color:#ccc;margin-bottom:12px\">If you encounter any of these issues, don&#039;t waste any more time trying to clean it yourself:<\/p>\n      <ul>\n        <li>The infection recurs after cleaning (persistent backdoor or compromised admin account)<\/li>\n        <li>Google has blacklisted your domain (partial or total deindexing)<\/li>\n        <li>You do not have SSH access or the file permissions have been changed.<\/li>\n        <li>You have an e-commerce website with customer data (GDPR risk)<\/li>\n        <li>Your hosting provider refuses to reactivate the account without validation.<\/li>\n      <\/ul>\n    <\/div>\n\n    <div class=\"inline-cta\">\n      <h3>Is your website infected?<\/h3>\n      <p>MogaCode prend en charge le nettoyage complet, le hardening et la mise en place d'une surveillance active. Intervention rapide, g\u00e9n\u00e9ralement sous 24h.<\/p>\n      <a href=\"https:\/\/www.mogacode.ma\/en\/contact\/\" class=\"btn-white\">Request an intervention<\/a>\n    <\/div>\n\n    <h2>Etape 3, Durcissement post-nettoyage<\/h2>\n    <p>A cleaned but unhardened site will be reinfected. That&#039;s a certainty. Here are the essential measures:<\/p>\n\n    <h3>Secure wp-config.php<\/h3>\n    <div class=\"code-block\"># In .htaccess, block direct access to wp-config.php order allow,deny deny from all # Move wp-config.php one level above the web root. # WordPress will find it automatically.<\/div>\n\n    <h3>File permissions are correct.<\/h3>\n    <div class=\"code-block\">find . -type d -exec chmod 755 {} \\; find . -type f -exec chmod 644 {} \\; chmod 600 wp-config.php<\/div>\n\n    <h3>Enable two-factor authentication<\/h3>\n    <p>The &quot;WP 2FA&quot; or &quot;Google Authenticator&quot; plugin for WordPress adds a TOTP (Token of Validation) to the login page. This is the most effective measure against brute-force attacks on \/wp-admin.<\/p>\n\n    <h3>Implementing a WAF<\/h3>\n    <p>A Web Application Firewall (Wordfence Premium, Cloudflare WAF) blocks attacks before they even reach WordPress. On our Infomaniak servers, we systematically activate Wordfence with a geo-blocking rule targeting countries with high automated scanning activity.<\/p>\n\n    <h3>Never use useless plugins<\/h3>\n    <p>This is the most painful lesson. In April 2026, 21 of our clients&#039; websites were infected overnight via pirated versions of Elementor Pro, Ultimate Elementor, and RevSlider. These plugins all contained the same signature: <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">cAT3VWynuiL7CRgr<\/code>. A clean, discreet backdoor, already in place for weeks before activation.<\/p>\n\n    <div class=\"highlight-box\">\n      <h3>WordPress Hardening Checklist<\/h3>\n      <ul>\n        <li>Mise \u00e0 jour WordPress, themes et plugins, sans exception<\/li>\n        <li>Removal of inactive themes and plugins<\/li>\n        <li>Limitation of login attempts (Limit Login Attempts)<\/li>\n        <li>2FA authentication on all admin accounts<\/li>\n        <li>Weekly automatic security scan (Wordfence)<\/li>\n        <li>Automatic daily off-server backups<\/li>\n        <li>HTTPS enabled with HSTS<\/li>\n        <li>HTTP security headers (X-Frame-Options, CSP, X-Content-Type-Options)<\/li>\n        <li>Hiding the WordPress version (in the meta tags and RSS feed)<\/li>\n        <li>Disable xmlrpc.php if not used<\/li>\n      <\/ul>\n    <\/div>\n\n    <div class=\"author-box\">\n      <div class=\"author-avatar\">P<\/div>\n      <div class=\"author-info\">\n        <h4>Patrick Rary<\/h4>\n        <p>Fondateur MogaCode, Expert judiciaire informaticien, 30 ans d'experience IT. A nettoye plus de 80 sites WordPress infectes depuis 2020.<\/p>\n      <\/div>\n    <\/div>\n\n  <\/div>\n\n  <div class=\"article-cta-bottom\">\n    <h2>MogaCode Care, La maintenance qui previent<\/h2>\n    <p>Updates, backups, 24\/7 monitoring, active WAF. Your WordPress site is monitored without you having to think about it.<\/p>\n    <a href=\"https:\/\/www.mogacode.ma\/en\/sites-wordpress\/\" class=\"btn-orange\">Discover MogaCode Care<\/a>\n  <\/div>\n<\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Symptoms, diagnosis, cleanup, hardening, restoring Google visibility. The complete procedure MogaCode applies to compromised sites.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,16],"tags":[],"class_list":["post-1663","post","type-post","status-publish","format-standard","hentry","category-s-curit-wordpress","category-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Site WordPress Pirat\u00e9, Que Faire ? Guide 2026 | MogaCode<\/title>\n<meta name=\"description\" content=\"Sympt\u00f4mes d&#039;un site WordPress compromis, premi\u00e8re intervention, nettoyage, durcissement. La proc\u00e9dure que MogaCode applique sur les sites infect\u00e9s.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mon site WordPress est pirat\u00e9 : la proc\u00e9dure exacte qu&#039;on applique sur les sites infect\u00e9s\" \/>\n<meta property=\"og:description\" content=\"Sympt\u00f4mes d&#039;un site WordPress compromis, premi\u00e8re intervention, nettoyage, durcissement. La proc\u00e9dure que MogaCode applique sur les sites infect\u00e9s.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/\" \/>\n<meta property=\"og:site_name\" content=\"Mogacode\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-01T14:23:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-23T14:35:44+00:00\" \/>\n<meta name=\"author\" content=\"Patrick\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@mogacode\" \/>\n<meta name=\"twitter:site\" content=\"@mogacode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Patrick\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Site WordPress Pirat\u00e9, Que Faire ? Guide 2026 | MogaCode","description":"Symptoms of a compromised WordPress site, first intervention, cleanup, hardening. The procedure MogaCode applies to infected sites.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/","og_locale":"en_US","og_type":"article","og_title":"Mon site WordPress est pirat\u00e9 : la proc\u00e9dure exacte qu'on applique sur les sites infect\u00e9s","og_description":"Sympt\u00f4mes d'un site WordPress compromis, premi\u00e8re intervention, nettoyage, durcissement. La proc\u00e9dure que MogaCode applique sur les sites infect\u00e9s.","og_url":"https:\/\/www.mogacode.ma\/en\/site-wordpress-pirate-que-faire\/","og_site_name":"Mogacode","article_publisher":"https:\/\/www.facebook.com\/mogacode","article_author":"https:\/\/www.facebook.com\/mogacode","article_published_time":"2026-05-01T14:23:16+00:00","article_modified_time":"2026-05-23T14:35:44+00:00","author":"Patrick","twitter_card":"summary_large_image","twitter_creator":"@mogacode","twitter_site":"@mogacode","twitter_misc":{"Written by":"Patrick","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[]}},"_links":{"self":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/comments?post=1663"}],"version-history":[{"count":10,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1663\/revisions"}],"predecessor-version":[{"id":1790,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1663\/revisions\/1790"}],"wp:attachment":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/media?parent=1663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/categories?post=1663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/tags?post=1663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}