1. Home
  2. Security
  3. Pair Malware Security
  4. WordPress Malware Cleanup and Security Guide

WordPress Malware Cleanup and Security Guide

Use this guide to remove detected malware from a WordPress site and complete the security work needed to reduce the risk of another compromise. You can follow these steps whether you discovered the malware yourself or were notified by the Pair Security Team. 

If the compromised site is still publicly accessible, restrict access before beginning the cleanup. This helps protect your site files, visitors, and domain reputation while you work. If access is already restricted, it is best that protection remains in place until the cleanup is complete. 

Note: Cleaning a compromised site requires you to determine which files and code belong to the site. Deleting an unfamiliar file without checking it can damage the file, while removing only the obvious malware can leave hidden access behind. If you are not comfortable with inspecting and editing website files, we suggest Pair Malware Security’s ThreatShield or Complete Security. 

Securing WordPress Checklist

A complete cleanup includes the following steps: 

  1. Remove the malware
  2. Update WordPress
  3. Secure account access
  4. Secure the WordPress Configuration

Before You Begin

You will need access to: 

  • The Account Control Center (ACC)
  • The WordPress administration dashboard
  • The site files via the ACC file manager or SFTP/SSH

Use a trusted device while completing the cleanup. If you believe your device may be compromised, scan and secure that device before cleaning or securing your site. 

Backup the Current Site

Create a backup of the current website files and database before making changes. The backup may contain malware, but it gives you a reference copy if a cleanup step removes something the site needs. 

  • Do not overwrite older backups. An older copy may be the only clean version available. 
  • Label the new backup clearly as a post-compromise or infected backup. 
  • Keep an untouched copy in a secure location outside the affected website directory.
  • Do not restore this backup as a clean copy unless it has been inspected and cleared. 

See: 

Step 1: Review the Malware Scan Results

Log in to the ACC and open the Pair Malware Security dashboard. See Accessing the Pair Malware Security Dashboard.

Review the details for every listed file. As a general rule: 

If…Then…
A file was added during the compromiseRemove the file after confirming that it is not required by the site. 
A WordPress core file contains malicious codeReplace it with a clean copy from WordPress.org. 
A plugin or theme file contains malicious codeRemove the affected plugin or theme directory and assess whether a clean copy can be reinstalled from a trusted source. If the plugin or theme has been neglected by its developer, it may be a source of malware. 
A custom file contains malicious codeCompare it with a known-clean copy and remove the injected code, or replace the file with a clean backup. 

Every file listed in the Pair Malware Security dashboard should be addressed. 

See: 

Step 2: Choose a Cleanup Method

You can restore a known-clean backup or clean the affected files manually. 

Option A: Restore a Known-Clean Backup

A known-clean backup must have been created before the site was compromised. A backup created before the malware was discovered is not necessarily clean, since the infection may have been present for some time before it was detected. You must verify the backup is clean before restoring it. 

To use a backup: 

  1. Confirm that the backup predates the earliest known signs of the compromise.
  2. Restore the affected website files and database. 
  3. Review the Pair Malware Security dashboard again and address any remaining detections. 
  4. Complete all the security steps in this article, including updates and credential changes. 

Restoring a backup returns the restored files and database to the state captured in that backup. It does not resolve the security issue that allowed the compromise or remove credentials that may have been exposed. 

Option B: Clean the Files Manually

Work through the Pair Malware Security dashboard one result at a time. Use the file path to locate each affected file in the ACC file manager, SFTP, or SSH. 

Ensure every listed file is cleaned of malicious code. You can edit each file manually, but replacing the file with a clean copy from its original source is recommended whenever possible. 

Replace Compromised WordPress Core Files

WordPress core files include the standard files supplied with WordPress and the contents of wp-admin and wp-includes directories. 

  1. Determine which WordPress version the site currently uses. 
  2. Download a clean copy of that version from the official WordPress release archive. 
  3. Replace the affected core files with files from the clean download. 
  4. Replace the wp-admin and wp-includes directories if malware is identified within them. Removing the old directories before uploading their clean replacements prevents extra malicious files from being left behind. 
  5. Preserve wp-config.php and the wp-content directory. They contain site specific configuration, plugins, themes, and uploads and must be reviewed separately. 
  6. Review .htaccess carefully. This file may contain legitimate site rules, but it is also commonly modified during a compromise. Compare it with a known-clean copy whenever possible. 

Replace Compromised Plugins and Themes

For each affected plugin or theme: 

  1. Confirm whether the site still needs it. 
  2. Remove plugins and themes that are unfamiliar, unused, abandoned, or no longer supported. 
  3. Download a clean copy from the WordPress plugin directory, the WordPress theme directory, or the developer that originally supplied it. 
  4. Delete the affected plugin or theme directory before installing the clean copy. Copying new files over an infected directory can leave malicious files behind. 

Do not reinstall software from an unverified download, an old copy of uncertain origin, or a site distributing modified premium software. 

Clean Custom Files and Uploads

Files in a custom plugin, custom theme, or other site-specific directory cannot always be replaced from WordPress.org. In this instance, you can: 

  • Compare the affected file with a known-clean backup or the developer’s original copy. 
  • Remove only the injected code when the legitimate file contains custom work that must be preserved. 
  • Remove attacker created files identified by the Pair Malware Security dashboard.
  • Review the site’s configured uploads directory, usually wp-content/uploads, for PHP files or other scripts. This directory normally stores media, so files capable of running code should be investigated. 

If you cannot separate malicious code from legitimate code, stop and work with the site’s developer or choose Pair Malware Security’s ThreatShield or Complete Security tiers. Guessing can leave the malware and break your site. 

See: 

Step 3: Update WordPress, Plugins, and Themes

After cleaning or replacing the affected files, update the site so it receives the latest security fixes. 

Update WordPress

  1. Log in to the WordPress admin dashboard. 
  2. Go to Dashboard > Updates.
  3. Install the latest WordPress release. 
  4. If WordPress prompts you to update the database, follow the on-screen instructions. 

If you cannot use the dashboard, follow the manual WordPress update instructions. 

Update Plugins and Themes

  1. Log in to the WordPress admin dashboard. 
  2. Go to Dashboard > Updates.
  3. Install all available plugin and theme updates. 
  4. If the site uses premium plugins or themes that do not update through WordPress, check the developer’s official website or the marketplace where they were purchased for current versions. 

Reminder: Remove any unused plugins or themes. Replace anything that is abandoned or cannot be updated to a supported version. 

If an update causes compatibility issues, work with the site developer to repair or replace the affected component. Leaving outdated or vulnerable software installed can increase the risk of another compromise. 

See: 

Step 4. Remove Unwanted WordPress Users

A compromise site may contain WordPress users added without your permission, so review the account list and remove any users you do not recognize or no longer need.

  1. Log in to the WordPress admin dashboard. 
  2. Go to Users > All Users.
  3. Confirm that you recognize the username and email address. 
  1. Remove unfamiliar or unnecessary users.
  2. Check that the remaining users have only the permissions they need. 

See: 

Step 5: Change all WordPress User Passwords

Change the password for every account on the WordPress site, including accounts belonging to other people. You can use a WordPress plugin for this, or complete the process manually by following the steps below:

  1. Log in to the WordPress admin dashboard. 
  2. Go to Users > All Users.
  3. Click on the username to edit it.
  4. Scroll down to the New Password section and click Generate Password button.
  5. Use the generated password or enter a new custom password.
  6. Click Update User button.
  7. Repeat these steps for each WordPress user.

It’s important to change the passwords after the malware has been removed. Otherwise, malicious code that remains on the site may capture the new credentials. 

See: 

Step 6: Change Hosting and File-Access Credentials 

Complete this step after removing the malware, and use a trusted device when setting the new credentials.

  1. Change the password for the Pair hosting account used to access the ACC.
  2. Change the password for every FTP login. 
  3. Review who has SSH access to the account and which public keys are authorized. Remove any access or keys you do not recognise. For each key you still use, generate a new key pair, confirm that it works, and then remove the old public key. 
  4. Update any authorized applications, scripts, or file-transfer clients that use the previous credentials. 

See: 

Step 7: Change the WordPress Database Password

Next, change your WordPress database password. 

See: 

Step 8: Regenerate the WordPress Security Keys and Salts

WordPress security keys and salts help protect login cookies. Replacing them invalidates existing WordPress sessions and signs all users out, including anyone who may have broken in during the compromise. 

You can regenerate the WordPress security keys and salts with a WordPress plugin, or complete the process manually by following these steps:

  1. Save a backup copy of wp-config.php.
  2. Open the official WordPress secret key generator.
  3. Copy the block of text it gives you.
  4. Open wp-config.php and find the section labeled “Authentication Unique keys and Salts.”
  5. Replace the existing key and salt definitions with the copied text block from Step 3.
  6. Save the file, then sign back in to WordPress. 

Step 9: Correct Insecure File Permissions

To improve security, configure file and directory permissions so they grant only the access your site requires. Exact requirements vary by site, but common WordPress settings are: 

ItemCommon Setting
Directories755
Regular Files644
Sensitive configuration files, including wp-config.php600

Use the most restrictive permissions that allow the site to function. Do not set files or directories to 777, which grants read, write, and execute permissions to owner, group, and other users on the server. 

See: File Permissions

Step 10: Test the Site

Test the site before returning it to normal public use. 

  • Open the homepage and several internal pages. 
  • Check for unexpected redirects, pop-ups, spam content, or unfamiliar links.
  • Confirm that the WordPress dashboard loads correctly. 
  • Check for missing images, broken layouts, PHP errors, or database errors. 

Malware and code injections can alter or delete files that WordPress needs. Removing the malware may not repair damage that has already occurred. Restore damaged files or content from a known clean backup, or work with the site’s developer to repair the affected functionality. If you need help repairing your site or building a new one, see: 

Step 11: Complete the Final Review

Confirm that: 

  • Every file listed in the Pair Malware Security dashboard was cleaned, replaced, or removed. 
  • WordPress, plugins, and themes were updated. 
  • All WordPress user passwords were changed. 
  • Unwanted user accounts were removed.
  • The hosting account password and any additional file access credentials were changed. 
  • SSH public keys were reviewed and reset. 
  • The database password was changed, and wp-config.php was updated where required.
  • The WordPress security keys and salts were regenerated. 
  • Insecure permissions were corrected. 

If Pair Networks is assisting with the incident, reply to the security email and confirm you have completed the cleanup and security steps. If you restricted access to your website, you can remove the restriction once the cleanup is complete and you have confirmed that the site works normally. If Pair Networks restricted access, wait for the security team to restore it. 

Continue Monitoring the Site

Continue monitoring the site for unexpected changes. Keep WordPress, plugins, and themes updated, remove software you no longer use, maintain current off-site backups, enable two-factor authentication when available, and limit administrator access to people who need it. If you want help with the day-to-day maintenance, consider our Care service. See Care.

If Google or another service flagged the site as dangerous, follow that provider’s review process after cleanup. For Google Search Console, open the “Security Issues” report and request review once the site is clean. See Google’s instructions for dangerous site warnings. 

Pair support can help you access the Pair Malware Security dashboard, locate files in the ACC, and find relevant documentation. Support cannot determine which custom code is legitimate, rewrite compromised files, or complete a manual cleanup for you. 

If you cannot finish the cleanup, contact Pair Networks and ask about: 

  • ThreatShield: A tool that automatically scans for detected malware and cleans or quarantines affected files. 
  • Complete Security: A security specialist removes the malware and completes security work to harden your WordPress against future attacks. Complete Security comes with one year of ThreatShield included. 

Pair Resources

WordPress Resources

Updated on October 9, 2026

Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support