我的WordPress站点被302重定向至陌生网站,如何解决?
WordPress站点被恶意302重定向的解决方案
问题详情
我的WordPress站点会自动跳转到陌生网站,重定向检测工具结果如下:
Result https://boshoneboshonto.com/ 302 Found https://yooshahpuwai.lol/?u=k8pp605&o=c9ewtnr&t=ggdown 200 OK Problems found: You use a 302 redirect. This means, that the actually content is temporary not reachable and will come back soon. To use a 302 redirection for generally moved pages is a bad idea. Search engine bot might not follow it or handle it as temporary. For SEO this is also a bad idea, because no link juice will be transferred to the linked page >>> https://boshoneboshonto.com/ > -------------------------------------------- > 302 Found > -------------------------------------------- Status: 302 Found Code: 302 Connection: close Location: https://yooshahpuwai.lol/?u=k8pp605&o=c9ewtnr&t=ggdown content-type: text/html; charset=UTF-8 cache-control: no-cache, no-store, must-revalidate, max-age=0 expires: Sat, 24 Feb 2024 11:57:22 GMT content-length: 0 date: Sat, 24 Feb 2024 11:57:22 GMT server: LiteSpeed vary: Accept-Encoding alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46" >>> https://yooshahpuwai.lol/?u=k8pp605&o=c9ewtnr&t=ggdown > -------------------------------------------- > 200 OK > -------------------------------------------- Status: 200 OK Code: 200 Server: nginx Date: Sat, 24 Feb 2024 11:57:23 GMT Content-Type: text/html Content-Length: 61514 Connection: close cache-control: private set-cookie: s1=m3e1b7oghosbztvr; path=/ Cache-Control: no-transform
已尝试在functions.php中添加remove_action('template_redirect', 'redirect_canonical');,但问题仍未解决。
解决方案步骤
1. 排查核心文件与插件中的恶意代码
- 主题文件检查:打开当前主题的
functions.php、header.php、footer.php,查找是否存在陌生的header("Location: ...")、wp_redirect()或echo '<meta http-equiv="refresh" ...>'代码,重点看文件开头、结尾以及注释隐藏的内容。 - 插件排查:一次性禁用所有插件,测试站点是否还会跳转。如果恢复正常,逐个启用插件,定位出导致跳转的问题插件并删除。
- wp-config.php检查:查看该文件是否被篡改,比如
WP_HOME、WP_SITEURL被修改为恶意站点,或者文件末尾被添加陌生代码段。 - .htaccess文件检查:备份当前
.htaccess后,清空内容,替换为WordPress默认规则:
替换后测试站点是否恢复正常。# BEGIN WordPress <IfModule mod_rewrite.c> RewriteEngine On RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> # END WordPress
2. 服务器层面排查
- 站点返回头显示服务器为LiteSpeed,可能存在服务器端的恶意配置:
- 联系主机商,检查虚拟主机的重定向设置、CDN缓存规则(若使用CDN)是否被篡改。
- 排查服务器上是否存在恶意脚本或未授权的配置修改,比如全局PHP配置文件、服务器级别的.htaccess文件。
3. 恶意软件扫描
- 使用WordPress安全插件(如Wordfence、Sucuri SiteCheck)对站点进行全面扫描,检测被篡改的文件、后门程序和恶意代码,按照插件提示清理威胁。
4. 修复文件权限
- 设置正确的文件权限:目录权限设为
755,文件权限设为644,防止恶意脚本被写入或执行。
5. 重新安装WordPress核心文件
- 在WordPress后台的「仪表盘」→「更新」页面,点击「重新安装WordPress」,替换被篡改的核心文件(此操作不会删除内容、主题和插件)。
内容的提问来源于stack exchange,提问作者Tony M. Gibson
相关产品推荐
相关产品推荐

