{"id":10771,"date":"2026-10-09T15:47:15","date_gmt":"2026-10-09T19:47:15","guid":{"rendered":"https:\/\/www.pair.com\/support\/kb\/?post_type=ht_kb&#038;p=10771"},"modified":"2026-10-09T15:47:19","modified_gmt":"2026-10-09T19:47:19","slug":"wordpress-malware-cleanup","status":"publish","type":"ht_kb","link":"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/","title":{"rendered":"WordPress Malware Cleanup and Security Guide"},"content":{"rendered":"\n<p>Use this guide to remove detected malware from a WordPress site and complete the security work needed to reduce the risk of another compromise. You can follow these steps whether you discovered the malware yourself or were notified by the Pair Security Team.&nbsp;<\/p>\n\n\n\n<p>If the compromised site is still publicly accessible, restrict access before beginning the cleanup. This helps protect your site files, visitors, and domain reputation while you work. If access is already restricted, it is best that protection remains in place until the cleanup is complete.&nbsp;<\/p>\n\n\n\n<p>Note: Cleaning a compromised site requires you to determine which files and code belong to the site. Deleting an unfamiliar file without checking it can damage the file, while removing only the obvious malware can leave hidden access behind. If you are not comfortable with inspecting and editing website files, we suggest <a href=\"https:\/\/www.pair.com\/security\/\">Pair Malware Security\u2019s <\/a><a href=\"https:\/\/www.pair.com\/security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Thr<\/a><a href=\"https:\/\/www.pair.com\/security\/\">eatShield or Complete Security<\/a>.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Securing WordPress Checklist<\/h2>\n\n\n\n<p>A complete cleanup includes the following steps:\u00a0<\/p>\n\n\n\n<ol style=\"margin: 0; padding-left: 24px;\">\n  <li style=\"margin: 0 0 10px; padding: 0;\">\n    <strong>Remove the malware<\/strong>\n    <ul style=\"list-style: none; margin: 4px 0 0; padding: 0;\">\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Clean, replace, or remove every affected file listed in the Pair Malware Security dashboard.<\/label>\n      <\/li>\n    <\/ul>\n  <\/li>\n\n  <li style=\"margin: 0 0 10px; padding: 0;\">\n    <strong>Update WordPress<\/strong>\n    <ul style=\"list-style: none; margin: 4px 0 0; padding: 0;\">\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Upgrade WordPress to the latest release.<\/label>\n      <\/li>\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Update all plugins and themes.<\/label>\n      <\/li>\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Repair or replace any component that cannot be safely updated.<\/label>\n      <\/li>\n    <\/ul>\n  <\/li>\n\n  <li style=\"margin: 0 0 10px; padding: 0;\">\n    <strong>Secure account access<\/strong>\n    <ul style=\"list-style: none; margin: 4px 0 0; padding: 0;\">\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Reset all WordPress user passwords.<\/label>\n      <\/li>\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Review all WordPress user accounts.<\/label>\n      <\/li>\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Change the hosting account password and all FTP\/SFTP and SSH credentials that can access site files.<\/label>\n      <\/li>\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Review authorized SSH public keys. Remove any you do not recognize and replace the keys you will use.<\/label>\n      <\/li>\n    <\/ul>\n  <\/li>\n\n  <li style=\"margin: 0; padding: 0;\">\n    <strong>Secure the WordPress Configuration<\/strong>\n    <ul style=\"list-style: none; margin: 4px 0 0; padding: 0;\">\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Change the WordPress database password.<\/label>\n      <\/li>\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Regenerate the WordPress security keys and salts.<\/label>\n      <\/li>\n      <li style=\"margin: 0; padding: 0;\">\n        <label style=\"margin: 0;\"><input type=\"checkbox\"> Correct insecure file and directory permissions.<\/label>\n      <\/li>\n    <\/ul>\n  <\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Before You Begin<\/h2>\n\n\n\n<p>You will need access to:&nbsp;<\/p>\n\n\n\n<ul>\n<li>The Account Control Center (ACC)<\/li>\n\n\n\n<li>The WordPress administration dashboard<\/li>\n\n\n\n<li>The site files via the ACC file manager or SFTP\/SSH<\/li>\n<\/ul>\n\n\n\n<p>Use a trusted device while completing the cleanup. If you believe your device may be compromised, scan and secure that device before cleaning or securing your site.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Backup the Current Site<\/h3>\n\n\n\n<p>Create a backup of the current website files and database before making changes. The backup may contain malware, but it gives you a reference copy if a cleanup step removes something the site needs.&nbsp;<\/p>\n\n\n\n<ul>\n<li>Do not overwrite older backups. An older copy may be the only clean version available.&nbsp;<\/li>\n\n\n\n<li>Label the new backup clearly as a post-compromise or infected backup.&nbsp;<\/li>\n\n\n\n<li>Keep an untouched copy in a secure location outside the affected website directory.<\/li>\n\n\n\n<li>Do not restore this backup as a clean copy unless it has been inspected and cleared.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-take-manual-file-backups-on-shared-vps-and-qs-dedicated\/\" target=\"_blank\" rel=\"noreferrer noopener\">Taking Manual File Backups on Shared, VPS, and Dedicated<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-take-database-backups-in-the-acc\/\" target=\"_blank\" rel=\"noreferrer noopener\">Taking Database Backups in the ACC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/manual-backups\/\" target=\"_blank\" rel=\"noreferrer noopener\">Taking Manual Backups on WP Hosting Accounts<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Review the Malware Scan Results<\/h2>\n\n\n\n<p>Log in to the ACC and open the Pair Malware Security dashboard. See<a href=\"https:\/\/www.pair.com\/support\/kb\/accessing-the-pair-malware-security-dashboard\" target=\"_blank\" rel=\"noreferrer noopener\"> Accessing the Pair Malware Security Dashboard<\/a>.<\/p>\n\n\n\n<p>Review the details for every listed file. As a general rule:\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>If\u2026<\/td><td>Then\u2026<\/td><\/tr><tr><td>A file was added during the compromise<\/td><td>Remove the file after confirming that it is not required by the site.&nbsp;<\/td><\/tr><tr><td>A WordPress core file contains malicious code<\/td><td>Replace it with a clean copy from <a href=\"http:\/\/wordpress.org\">WordPress.org<\/a>.&nbsp;<\/td><\/tr><tr><td>A plugin or theme file contains malicious code<\/td><td>Remove the affected plugin or theme directory and assess whether a clean copy can be reinstalled from a trusted source. If the plugin or theme has been neglected by its developer, it may be a source of malware.&nbsp;<\/td><\/tr><tr><td>A custom file contains malicious code<\/td><td>Compare it with a known-clean copy and remove the injected code, or replace the file with a clean backup.&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Every file listed in the Pair Malware Security dashboard should be addressed.&nbsp;<\/p>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/accessing-the-pair-malware-security-dashboard\" target=\"_blank\" rel=\"noreferrer noopener\">Accessing the Pair Malware Security Dashboard<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/malware-types-and-scan-results\" target=\"_blank\" rel=\"noreferrer noopener\">Understanding Malware Types and Scan Results<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Choose a Cleanup Method<\/h2>\n\n\n\n<p>You can restore a known-clean backup or clean the affected files manually.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Option A: Restore a Known-Clean Backup<\/h3>\n\n\n\n<p>A known-clean backup must have been created before the site was compromised. A backup created before the malware was discovered is not necessarily clean, since the infection may have been present for some time before it was detected. You must verify the backup is clean before restoring it.&nbsp;<\/p>\n\n\n\n<p>To use a backup:&nbsp;<\/p>\n\n\n\n<ol>\n<li>Confirm that the backup predates the earliest known signs of the compromise.<\/li>\n\n\n\n<li>Restore the affected website files and database.&nbsp;<\/li>\n\n\n\n<li>Review the Pair Malware Security dashboard again and address any remaining detections.&nbsp;<\/li>\n\n\n\n<li>Complete all the <a href=\"#step-3-update-wordpress-plugins-and-themes\">security steps<\/a> in this article, including updates and credential changes.\u00a0<\/li>\n<\/ol>\n\n\n\n<p>Restoring a backup returns the restored files and database to the state captured in that backup. It does not resolve the security issue that allowed the compromise or remove credentials that may have been exposed.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Option B: Clean the Files Manually<\/h3>\n\n\n\n<p>Work through the Pair Malware Security dashboard one result at a time. Use the file path to locate each affected file in the ACC file manager, SFTP, or SSH.&nbsp;<\/p>\n\n\n\n<p>Ensure every listed file is cleaned of malicious code. You can edit each file manually, but replacing the file with a clean copy from its original source is recommended whenever possible.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Replace Compromised WordPress Core Files<\/h4>\n\n\n\n<p>WordPress core files include the standard files supplied with WordPress and the contents of <code>wp-admin<\/code> and <code>wp-includes<\/code> directories.\u00a0<\/p>\n\n\n\n<ol>\n<li>Determine which WordPress version the site currently uses.&nbsp;<\/li>\n\n\n\n<li>Download a clean copy of that version from the <a href=\"https:\/\/wordpress.org\/download\/releases\/\">official WordPress release archive<\/a>.&nbsp;<\/li>\n\n\n\n<li>Replace the affected core files with files from the clean download.&nbsp;<\/li>\n\n\n\n<li>Replace the <code>wp-admin<\/code> and <code>wp-includes<\/code> directories if malware is identified within them. Removing the old directories before uploading their clean replacements prevents extra malicious files from being left behind.\u00a0<\/li>\n\n\n\n<li>Preserve <code>wp-config.php<\/code> and the <code>wp-content<\/code> directory. They contain site specific configuration, plugins, themes, and uploads and must be reviewed separately.\u00a0<\/li>\n\n\n\n<li>Review .<code>htaccess<\/code> carefully. This file may contain legitimate site rules, but it is also commonly modified during a compromise. Compare it with a known-clean copy whenever possible.\u00a0<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">Replace Compromised Plugins and Themes<\/h4>\n\n\n\n<p>For each affected plugin or theme:&nbsp;<\/p>\n\n\n\n<ol>\n<li>Confirm whether the site still needs it.&nbsp;<\/li>\n\n\n\n<li>Remove plugins and themes that are unfamiliar, unused, abandoned, or no longer supported.&nbsp;<\/li>\n\n\n\n<li>Download a clean copy from the <a href=\"https:\/\/wordpress.org\/plugins\/\">WordPress plugin directory<\/a>, the<a href=\"https:\/\/wordpress.org\/themes\/\"> WordPress theme directory<\/a>, or the developer that originally supplied it.&nbsp;<\/li>\n\n\n\n<li>Delete the affected plugin or theme directory before installing the clean copy. Copying new files over an infected directory can leave malicious files behind.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>Do not reinstall software from an unverified download, an old copy of uncertain origin, or a site distributing modified premium software.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Clean Custom Files and Uploads<\/h4>\n\n\n\n<p>Files in a custom plugin, custom theme, or other site-specific directory cannot always be replaced from WordPress.org. In this instance, you can:&nbsp;<\/p>\n\n\n\n<ul>\n<li>Compare the affected file with a known-clean backup or the developer\u2019s original copy.&nbsp;<\/li>\n\n\n\n<li>Remove only the injected code when the legitimate file contains custom work that must be preserved.&nbsp;<\/li>\n\n\n\n<li>Remove attacker created files identified by the Pair Malware Security dashboard.<\/li>\n\n\n\n<li>Review the site\u2019s configured uploads directory, usually <code>wp-content\/uploads<\/code>, for PHP files or other scripts. This directory normally stores media, so files capable of running code should be investigated.\u00a0<\/li>\n<\/ul>\n\n\n\n<p>If you cannot separate malicious code from legitimate code, stop and work with the site\u2019s developer or choose <a href=\"https:\/\/www.pair.com\/security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pair Malware Security\u2019s ThreatShield or Complete Security tiers<\/a>. Guessing can leave the malware and break your site.\u00a0<\/p>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-edit-files-in-the-acc\/\">Editing Files in the ACC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-upload-files\/\">Uploading Files in the ACC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/connecting-with-ssh\/\">Connect to Your Pair Account with SSH<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/uploading-files-using-ftp\/\">Using FTP with Hosting Accounts<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Update WordPress, Plugins, and Themes<\/h2>\n\n\n\n<p>After cleaning or replacing the affected files, update the site so it receives the latest security fixes.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Update WordPress<\/h3>\n\n\n\n<ol>\n<li>Log in to the WordPress admin dashboard.&nbsp;<\/li>\n\n\n\n<li>Go to <strong>Dashboard<\/strong> > <strong>Updates<\/strong>.<\/li>\n\n\n\n<li>Install the latest WordPress release.&nbsp;<\/li>\n\n\n\n<li>If WordPress prompts you to update the database, follow the on-screen instructions.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>If you cannot use the dashboard, follow the <a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">manual WordPress update instructions<\/a>.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Update Plugins and Themes<\/h3>\n\n\n\n<ol>\n<li>Log in to the WordPress admin dashboard.&nbsp;<\/li>\n\n\n\n<li>Go to <strong>Dashboard<\/strong> > <strong>Updates<\/strong>.<\/li>\n\n\n\n<li>Install all available plugin and theme updates.&nbsp;<\/li>\n\n\n\n<li>If the site uses premium plugins or themes that do not update through WordPress, check the developer\u2019s official website or the marketplace where they were purchased for current versions.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>Reminder: Remove any unused plugins or themes. Replace anything that is abandoned or cannot be updated to a supported version.&nbsp;<\/p>\n\n\n\n<p>If an update causes compatibility issues, work with the site developer to repair or replace the affected component. Leaving outdated or vulnerable software installed can increase the risk of another compromise.&nbsp;<\/p>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/wordpress-updating-plugins\/\" target=\"_blank\" rel=\"noreferrer noopener\">Updating WordPress Plugins<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/wordpress-updating-themes\/\" target=\"_blank\" rel=\"noreferrer noopener\">Updating WordPress Themes<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4. Remove Unwanted WordPress Users<\/h2>\n\n\n\n<p>A compromise site may contain WordPress users added without your permission, so review the account list and remove any users you do not recognize or no longer need.<\/p>\n\n\n\n<ol>\n<li>Log in to the WordPress admin dashboard.&nbsp;<\/li>\n\n\n\n<li>Go to <strong>Users<\/strong> > <strong>All Users<\/strong>.<\/li>\n\n\n\n<li>Confirm that you recognize the username and email address.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol>\n<li>Remove unfamiliar or unnecessary users.<\/li>\n\n\n\n<li>Check that the remaining users have only the permissions they need.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/wordpress-user-roles-and-capabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress User Roles and Capabilities<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/users-screen\/\" target=\"_blank\" rel=\"noreferrer noopener\">Managing WordPress Users<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/reset-your-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">Resetting WordPress User Password<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 5: Change all WordPress User Passwords<\/h2>\n\n\n\n<p>Change the password for every account on the WordPress site, including accounts belonging to other people. You can use a WordPress plugin for this, or complete the process manually by following the steps below:<\/p>\n\n\n\n<ol>\n<li>Log in to the WordPress admin dashboard.&nbsp;<\/li>\n\n\n\n<li>Go to <strong>Users<\/strong> > <strong>All Users<\/strong>.<\/li>\n\n\n\n<li>Click on the username to edit it.<\/li>\n\n\n\n<li>Scroll down to the New Password section and click <strong>Generate Password<\/strong> button.<\/li>\n\n\n\n<li>Use the generated password or enter a new custom password.<\/li>\n\n\n\n<li>Click <strong>Update User <\/strong>button.<\/li>\n\n\n\n<li>Repeat these steps for each WordPress user.<\/li>\n<\/ol>\n\n\n\n<p>It\u2019s important to change the passwords after the malware has been removed. Otherwise, malicious code that remains on the site may capture the new credentials.&nbsp;<\/p>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/wordpress-user-roles-and-capabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress User Roles and Capabilities<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/users-screen\/\" target=\"_blank\" rel=\"noreferrer noopener\">Managing WordPress Users<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/reset-your-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">Resetting WordPress User Password<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 6: Change Hosting and File-Access Credentials&nbsp;<\/h2>\n\n\n\n<p>Complete this step after removing the malware, and use a trusted device when setting the new credentials.<\/p>\n\n\n\n<ol>\n<li>Change the password for the Pair hosting account used to access the ACC.<\/li>\n\n\n\n<li>Change the password for every FTP login.&nbsp;<\/li>\n\n\n\n<li>Review who has SSH access to the account and which public keys are authorized. Remove any access or keys you do not recognise. For each key you still use, generate a new key pair, confirm that it works, and then remove the old public key.&nbsp;<\/li>\n\n\n\n<li>Update any authorized applications, scripts, or file-transfer clients that use the previous credentials.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/changing-resetting-account-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing or Resetting Your Account Password<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/changing-ftp-login-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing an FTP Login Password<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/manage-ssh-access\/\" target=\"_blank\" rel=\"noreferrer noopener\">Managing SSH Access on Pair Accounts<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/deleting-ssh-keys\/\" target=\"_blank\" rel=\"noreferrer noopener\">Deleting SSH Keys<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 7: Change the WordPress Database Password<\/h2>\n\n\n\n<p>Next, change your WordPress database password.\u00a0<\/p>\n\n\n\n<p>See:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/changing-a-wordpress-database-password-on-shared-and-vps\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing a WordPress Database Password on Shared and VPS<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/change-wordpress-database-password-managed-wordpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing a WordPress Database Password on Managed WordPress and Podcast Websites<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 8: Regenerate the WordPress Security Keys and Salts<\/h2>\n\n\n\n<p>WordPress security keys and salts help protect login cookies. Replacing them invalidates existing WordPress sessions and signs all users out, including anyone who may have broken in during the compromise.&nbsp;<\/p>\n\n\n\n<p>You can regenerate the WordPress security keys and salts with a WordPress plugin, or complete the process manually by following these steps:<\/p>\n\n\n\n<ol>\n<li>Save a backup copy of <code>wp-config.php<\/code>.<\/li>\n\n\n\n<li>Open the <a href=\"https:\/\/api.wordpress.org\/secret-key\/1.1\/salt\/\" target=\"_blank\" rel=\"noreferrer noopener\">official WordPress secret key generator<\/a>.<\/li>\n\n\n\n<li>Copy the block of text it gives you.<\/li>\n\n\n\n<li>Open <code>wp-config.php<\/code> and find the section labeled \u201cAuthentication Unique keys and Salts.\u201d<\/li>\n\n\n\n<li>Replace the existing key and salt definitions with the copied text block from Step 3.<\/li>\n\n\n\n<li>Save the file, then sign back in to WordPress.&nbsp;<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Step 9: Correct Insecure File Permissions<\/h2>\n\n\n\n<p>To improve security, configure file and directory permissions so they grant only the access your site requires. Exact requirements vary by site, but common WordPress settings are:&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Item<\/td><td>Common Setting<\/td><\/tr><tr><td>Directories<\/td><td>755<\/td><\/tr><tr><td>Regular Files<\/td><td>644<\/td><\/tr><tr><td>Sensitive configuration files, including <code>wp-config.php<\/code><\/td><td>600<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Use the most restrictive permissions that allow the site to function. Do not set files or directories to 777, which grants read, write, and execute permissions to owner, group, and other users on the server.&nbsp;<\/p>\n\n\n\n<p>See: <a href=\"https:\/\/www.pair.com\/support\/kb\/file-permissions\/\" target=\"_blank\" rel=\"noreferrer noopener\">File Permissions<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 10: Test the Site<\/h2>\n\n\n\n<p>Test the site before returning it to normal public use.&nbsp;<\/p>\n\n\n\n<ul>\n<li>Open the homepage and several internal pages.&nbsp;<\/li>\n\n\n\n<li>Check for unexpected redirects, pop-ups, spam content, or unfamiliar links.<\/li>\n\n\n\n<li>Confirm that the WordPress dashboard loads correctly.&nbsp;<\/li>\n\n\n\n<li>Check for missing images, broken layouts, PHP errors, or database errors.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Malware and code injections can alter or delete files that WordPress needs. Removing the malware may not repair damage that has already occurred. Restore damaged files or content from a known clean backup, or work with the site\u2019s developer to repair the affected functionality. If you need help repairing your site or building a new one, see:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/rebuild\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pair Rebuild<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/custom-web-design\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pair Custom Web Design<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/quicksite\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pair QuickSite<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 11: Complete the Final Review<\/h2>\n\n\n\n<p>Confirm that:&nbsp;<\/p>\n\n\n\n<ul>\n<li>Every file listed in the Pair Malware Security dashboard was cleaned, replaced, or removed.\u00a0<\/li>\n\n\n\n<li>WordPress, plugins, and themes were updated.&nbsp;<\/li>\n\n\n\n<li>All WordPress user passwords were changed.&nbsp;<\/li>\n\n\n\n<li>Unwanted user accounts were removed.<\/li>\n\n\n\n<li>The hosting account password and any additional file access credentials were changed.&nbsp;<\/li>\n\n\n\n<li>SSH public keys were reviewed and reset.&nbsp;<\/li>\n\n\n\n<li>The database password was changed, and <code>wp-config.php<\/code> was updated where required.<\/li>\n\n\n\n<li>The WordPress security keys and salts were regenerated.&nbsp;<\/li>\n\n\n\n<li>Insecure permissions were corrected.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>If Pair Networks is assisting with the incident, reply to the security email and confirm you have completed the cleanup and security steps. If you restricted access to your website, you can remove the restriction once the cleanup is complete and you have confirmed that the site works normally. If Pair Networks restricted access, wait for the security team to restore it.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Continue Monitoring the Site<\/h2>\n\n\n\n<p>Continue monitoring the site for unexpected changes. Keep WordPress, plugins, and themes updated, remove software you no longer use, maintain current off-site backups, enable two-factor authentication when available, and limit administrator access to people who need it. If you want help with the day-to-day maintenance, consider our Care service. See<a href=\"https:\/\/www.pair.com\/care\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Care<\/a>.<\/p>\n\n\n\n<p>If Google or another service flagged the site as dangerous, follow that provider\u2019s review process after cleanup. For Google Search Console, open the \u201cSecurity Issues\u201d report and request review once the site is clean. See <a href=\"https:\/\/support.google.com\/webmasters\/answer\/6347750\" target=\"_blank\" rel=\"noreferrer noopener\">Google\u2019s instructions for dangerous site warnings<\/a>.\u00a0<\/p>\n\n\n\n<p>Pair support can help you access the Pair Malware Security dashboard, locate files in the ACC, and find relevant documentation. Support cannot determine which custom code is legitimate, rewrite compromised files, or complete a manual cleanup for you.&nbsp;<\/p>\n\n\n\n<p>If you cannot finish the cleanup, contact Pair Networks and ask about:&nbsp;<\/p>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/security\/\" target=\"_blank\" rel=\"noreferrer noopener\">ThreatShield<\/a>: A tool that automatically scans for detected malware and cleans or quarantines affected files.\u00a0<\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Complete Security<\/a>: A security specialist removes the malware and completes security work to harden your WordPress against future attacks. Complete Security comes with one year of ThreatShield included.\u00a0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Related Resources<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Pair Resources<\/h3>\n\n\n\n<ul>\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-take-manual-file-backups-on-shared-vps-and-qs-dedicated\/\" target=\"_blank\" rel=\"noreferrer noopener\">Taking Manual File Backups on Shared, VPS, and Dedicated<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-take-database-backups-in-the-acc\/\" target=\"_blank\" rel=\"noreferrer noopener\">Taking Database Backups in the ACC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/manage-wp-hosting-backups\/\">Managing WordPress Hosting Backups<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-edit-files-in-the-acc\/\" target=\"_blank\" rel=\"noreferrer noopener\">Editing Files in the ACC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/how-to-upload-files\/\">Uploading Files in the ACC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/using-phpmyadmin\/\">Accessing phpMyAdmin in the ACC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/wordpress-passwords\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress Passwords<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/changing-resetting-account-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing or Resetting Your Account Password<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/changing-ftp-login-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing an FTP Login Password<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/manage-ssh-access\/\" target=\"_blank\" rel=\"noreferrer noopener\">Managing SSH Access on Pair Accounts<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/deleting-ssh-keys\/\" target=\"_blank\" rel=\"noreferrer noopener\">Deleting SSH Keys<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/changing-a-wordpress-database-password-on-shared-and-vps\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing a WordPress Database Password on Shared and VPS<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/change-wordpress-database-password-managed-wordpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">Changing a WordPress Database Password on Managed WordPress and Podcast Websites<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/support\/kb\/file-permissions\/\" target=\"_blank\" rel=\"noreferrer noopener\">File Permissions<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.pair.com\/security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pair Malware Security<\/a><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">WordPress Resources<\/h3>\n\n\n\n<ul>\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/faq-my-site-was-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">FAQ My Site Was Hacked<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">Updating WordPress<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/dashboard-updates-screen\/\" target=\"_blank\" rel=\"noreferrer noopener\">Dashboard Updates<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/manage-plugins\/\" target=\"_blank\" rel=\"noreferrer noopener\">Managing Plugins<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/users-screen\/\" target=\"_blank\" rel=\"noreferrer noopener\">Managing WordPress Users<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/reset-your-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">Resetting WordPress User Password<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/developer.wordpress.org\/apis\/wp-config-php\/\" target=\"_blank\" rel=\"noreferrer noopener\">Editing a wp-config.php File<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/developer.wordpress.org\/advanced-administration\/security\/hardening\/\" target=\"_blank\" rel=\"noreferrer noopener\">Hardening WordPress<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Use this guide to remove detected malware from a WordPress site and complete the security work needed to reduce the risk of another compromise. You can follow these steps whether you discovered the malware yourself or were notified by the Pair Security Team.&nbsp; If the compromised site is still publicly&#8230;<\/p>\n","protected":false},"author":11,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":[],"ht-kb-category":[229],"ht-kb-tag":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.8.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>WordPress Malware Cleanup and Security Guide | Pair<\/title>\n<meta name=\"description\" content=\"Follow our WordPress malware cleanup guide to remove malware, update software, reset passwords, and help prevent reinfection.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WordPress Malware Cleanup and Security Guide | Pair\" \/>\n<meta property=\"og:description\" content=\"Follow our WordPress malware cleanup guide to remove malware, update software, reset passwords, and help prevent reinfection.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/\" \/>\n<meta property=\"og:site_name\" content=\"Knowledge Base - Pair Networks\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/pairnetworks\/\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-09T19:47:19+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@pairNetworks\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/\",\"url\":\"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/\",\"name\":\"WordPress Malware Cleanup and Security Guide | Pair\",\"isPartOf\":{\"@id\":\"https:\/\/www.pair.com\/support\/kb\/#website\"},\"datePublished\":\"2026-10-09T19:47:15+00:00\",\"dateModified\":\"2026-10-09T19:47:19+00:00\",\"description\":\"Follow our WordPress malware cleanup guide to remove malware, update software, reset passwords, and help prevent reinfection.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.pair.com\/support\/kb\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WordPress Malware Cleanup and Security Guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.pair.com\/support\/kb\/#website\",\"url\":\"https:\/\/www.pair.com\/support\/kb\/\",\"name\":\"Knowledge Base - Pair Networks\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.pair.com\/support\/kb\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.pair.com\/support\/kb\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.pair.com\/support\/kb\/#organization\",\"name\":\"Pair Networks\",\"url\":\"https:\/\/www.pair.com\/support\/kb\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.pair.com\/support\/kb\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.pair.com\/support\/kb\/wp-content\/uploads\/2022\/02\/Gb_TUkUE_400x400.jpeg\",\"contentUrl\":\"https:\/\/www.pair.com\/support\/kb\/wp-content\/uploads\/2022\/02\/Gb_TUkUE_400x400.jpeg\",\"width\":360,\"height\":360,\"caption\":\"Pair Networks\"},\"image\":{\"@id\":\"https:\/\/www.pair.com\/support\/kb\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/pairnetworks\/\",\"https:\/\/twitter.com\/pairNetworks\",\"https:\/\/www.instagram.com\/pairnetworks\/\",\"https:\/\/www.linkedin.com\/company\/2269676\/\",\"https:\/\/www.pinterest.com\/pairnetworksinc\/pins\/\",\"https:\/\/www.youtube.com\/user\/pairnetworks\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WordPress Malware Cleanup and Security Guide | Pair","description":"Follow our WordPress malware cleanup guide to remove malware, update software, reset passwords, and help prevent reinfection.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/","og_locale":"en_US","og_type":"article","og_title":"WordPress Malware Cleanup and Security Guide | Pair","og_description":"Follow our WordPress malware cleanup guide to remove malware, update software, reset passwords, and help prevent reinfection.","og_url":"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/","og_site_name":"Knowledge Base - Pair Networks","article_publisher":"https:\/\/www.facebook.com\/pairnetworks\/","article_modified_time":"2026-10-09T19:47:19+00:00","twitter_card":"summary_large_image","twitter_site":"@pairNetworks","twitter_misc":{"Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/","url":"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/","name":"WordPress Malware Cleanup and Security Guide | Pair","isPartOf":{"@id":"https:\/\/www.pair.com\/support\/kb\/#website"},"datePublished":"2026-10-09T19:47:15+00:00","dateModified":"2026-10-09T19:47:19+00:00","description":"Follow our WordPress malware cleanup guide to remove malware, update software, reset passwords, and help prevent reinfection.","breadcrumb":{"@id":"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.pair.com\/support\/kb\/wordpress-malware-cleanup\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.pair.com\/support\/kb\/"},{"@type":"ListItem","position":2,"name":"WordPress Malware Cleanup and Security Guide"}]},{"@type":"WebSite","@id":"https:\/\/www.pair.com\/support\/kb\/#website","url":"https:\/\/www.pair.com\/support\/kb\/","name":"Knowledge Base - Pair Networks","description":"","publisher":{"@id":"https:\/\/www.pair.com\/support\/kb\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.pair.com\/support\/kb\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.pair.com\/support\/kb\/#organization","name":"Pair Networks","url":"https:\/\/www.pair.com\/support\/kb\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pair.com\/support\/kb\/#\/schema\/logo\/image\/","url":"https:\/\/www.pair.com\/support\/kb\/wp-content\/uploads\/2022\/02\/Gb_TUkUE_400x400.jpeg","contentUrl":"https:\/\/www.pair.com\/support\/kb\/wp-content\/uploads\/2022\/02\/Gb_TUkUE_400x400.jpeg","width":360,"height":360,"caption":"Pair Networks"},"image":{"@id":"https:\/\/www.pair.com\/support\/kb\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/pairnetworks\/","https:\/\/twitter.com\/pairNetworks","https:\/\/www.instagram.com\/pairnetworks\/","https:\/\/www.linkedin.com\/company\/2269676\/","https:\/\/www.pinterest.com\/pairnetworksinc\/pins\/","https:\/\/www.youtube.com\/user\/pairnetworks"]}]}},"_links":{"self":[{"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/ht-kb\/10771"}],"collection":[{"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/comments?post=10771"}],"version-history":[{"count":8,"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/ht-kb\/10771\/revisions"}],"predecessor-version":[{"id":10779,"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/ht-kb\/10771\/revisions\/10779"}],"wp:attachment":[{"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/media?parent=10771"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/ht-kb-category?post=10771"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.pair.com\/support\/kb\/wp-json\/wp\/v2\/ht-kb-tag?post=10771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}