Ripefruit

  • About Us
    • About Us
      • Acceptable Use
      • Privacy Policy
      • T & C
    • Contact Ripefruit
    • In Progress
    • Not For Profit
    • Partners
  • What We Do!
    • Advertising
    • Publications
    • Web Design
  • Clients
    • Billing
    • Client Login
    • Resources
      • Friends
      • Service Status
    • Support
  • IT Talk
    • Domain Names
    • Hosting
    • Internet
    • Search
    • Services
    • Software
    • Technical
  • Contact Us
    • Contact Us
    • Site Map
You are here: Home / IT Talk / Services / Hacked WordPress | What Next?

Hacked WordPress | What Next?

Unfortunately, hackers love targetting WordPress websites.

They are trying to get in via your WordPress Admin area.

The reality is, hackers already know two key elements about your login:

  • where to login (ie www.yourdomain.com/wp-admin)
  • your username (admin)*

* Now, how did we know your username was ‘admin’? By default, it is the username assigned during a WordPress installation and setup process and subsequently, billions of WordPress sites have the same username = admin. So, all the hacker has to figure out is your password and they are in.

Hackers use software that stores millions of common passwords, repeatedly trying to login. They also use something called Brute Force methods.

The bad news is a hacker may have already got in. We’ve heard thousands of instances where a hacker gets in, has a snoop around, adds some backdoor files and leaves without anyone knowing.

Sometimes they are just looking for sensitive data like credit card information.  Others come back weeks, sometimes months later via the backdoor file they left earlier.

OK, firstly, if your site has been hacked and all you see is Hacked by Hacker, then see Hacked by Hacker Fix for our 2 minute fix.

If your username is ‘admin’, then you need to change it, and change it NOW! Heres how..

To rename your WordPress ‘admin’ user:

  1. Sign in as ‘admin’.
  2. Create a new user using the steps below.
  3. Choose a hard-to-guess username, but don’t make it so difficult that you’ll forget it.
  4. Make that user’s role “administrator”.
  5. Choose a password that has upper and lower-case letters and numbers in it. Symbols are OK too.
  6. Click “Add new user”.
  7. Sign out as ‘admin’.
  8. Sign in as the new user.
  9. Delete your old ‘admin’ user and assign all posts/pages/comments to your new admin user.

Congratulations, you now have a more secure WordPress website.

Finally, do you want to know if a hacker has been in without your knowledge? Do you want to secure your web site against attacks in the future?

Here are 3 steps you must take to find out and secure your website so it does not happen in future.

  • Security Plugins | there are free and paid versions
    WP Security Scan (websitedefender) is free and will scan your website for bad and weak files
    In fact, if you search plugins for ‘websitedefender’, there are 3 free plugins that will go a long way towards securing your website
  • Security Plugin | Paid
    WordFence is very very good. Lots of advice, and regular mail advising you of risks. Its a small price to pay for peace-of-mind.
  • TimThumb has been a vulnerability for a while now. It is often installed with graphic-related plugins and some themes, so you will want to know if it is installed and then how to secure it so you are not at risk. Search plugins (add new) for TimThumb Vulnerability Scanner.

When I get emails from website owners who have been hacked we start with an investigation before advising how to proceed. Every hack is different and by a different hacker.   We look for things they have left behind.  We find out there IP address and block it.  We lock down the site to prevent future hacks.

Often, a WordPress web site can be unhacked and fixed in a few minutes (like Hacked by Hacker Fix).  Unfortunately with other hacks, multiple files are affected and a full reinstall is required.

Either way.. drop us a line and tell us your problem and we’ll work with you to fix it.

Cheers

KOZ

Source: Hacked WordPress | What Next?

Post Views: 518

Also See..


  • iThemes WordPress Security Webinar – Free
  • The BEST WordPress Security Plugin of all time
  • WordPress Admin Protection
  • Wordfence Security Audit Service
  • WordPress is Damn Good!

Recent Posts

  • WooCoomerce: Buy Now + Affiliate Link + Cart – FIXED
  • Why WP Engine Affiliate program migration from ShareASale to Everflow is a WASTE of time
  • how to hide nvidia pop up

About Brian King

Managing director and senior editor at Ripefruit Media

  • Email
  • Facebook
  • Twitter
  • YouTube

For Advertisers

  • Advertising FAQ
  • Contact Us
  • Content Changes
  • Website Network

IT Talk

  • WooCoomerce: Buy Now + Affiliate Link + Cart – FIXED
  • Why WP Engine Affiliate program migration from ShareASale to Everflow is a WASTE of time
  • how to hide nvidia pop up
  • Facebook Wishlist: Edit Featured Pin’s
  • What is the best shopping cart?
  • file explorer not responding FIX
  • Survey / Feedback cost time and money
  • Cloudflare Invoice Australian Tax Mistake

Keywords

admin affiliate apple australian avg backlink blocking brute force business cache change domain name email firefox fix form for sale fraud free google hosting how to htaccess ip ip address LastPass mobile mobile-friendly password plugin ranking removal remove responsive scam security seo software spam toontown update website web site Wordfence wordpress

SiteMap

  • About Us
  • Acceptable Use Policy
  • Advertising
  • Contact Us
  • Digital Publications
  • Domain Names
  • Email
  • Home Page
  • Hosting
  • Internet
  • Publishing
  • Software
  • Technical
  • Search
  • Services
  • Web Design
  • About Us
  • What We Do!
  • Clients
  • IT Talk
  • Contact Us


Copyright © 2025 · Ripefruit

Ripefruit acknowledges and pays respect to Aboriginal and Torres Strait Islander Elders past, present and future. We commit to building a kind future for everyone.