You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

我的WordPress站点被302重定向至陌生网站,如何解决?

WordPress站点被恶意302重定向的解决方案

问题详情

我的WordPress站点会自动跳转到陌生网站,重定向检测工具结果如下:

Result
https://boshoneboshonto.com/
302 Found
https://yooshahpuwai.lol/?u=k8pp605&o=c9ewtnr&t=ggdown
200 OK

Problems found:
You use a 302 redirect. This means, that the actually content is temporary not reachable and will come back soon. To use a 302 redirection for generally moved pages is a bad idea. Search engine bot might not follow it or handle it as temporary. For SEO this is also a bad idea, because no link juice will be transferred to the linked page

>>> https://boshoneboshonto.com/

> --------------------------------------------
> 302 Found
> --------------------------------------------

Status: 302 Found
Code:   302
Connection: close
Location:   https://yooshahpuwai.lol/?u=k8pp605&o=c9ewtnr&t=ggdown
content-type:   text/html; charset=UTF-8
cache-control:  no-cache, no-store, must-revalidate, max-age=0
expires:    Sat, 24 Feb 2024 11:57:22 GMT
content-length: 0
date:   Sat, 24 Feb 2024 11:57:22 GMT
server: LiteSpeed
vary:   Accept-Encoding
alt-svc:    h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"

>>> https://yooshahpuwai.lol/?u=k8pp605&o=c9ewtnr&t=ggdown

> --------------------------------------------
> 200 OK
> --------------------------------------------

Status: 200 OK
Code:   200
Server: nginx
Date:   Sat, 24 Feb 2024 11:57:23 GMT
Content-Type:   text/html
Content-Length: 61514
Connection: close
cache-control:  private
set-cookie: s1=m3e1b7oghosbztvr; path=/
Cache-Control:  no-transform

已尝试在functions.php中添加remove_action('template_redirect', 'redirect_canonical');,但问题仍未解决。


解决方案步骤

1. 排查核心文件与插件中的恶意代码

  • 主题文件检查:打开当前主题的functions.php、header.php、footer.php,查找是否存在陌生的header("Location: ...")、wp_redirect()或echo '<meta http-equiv="refresh" ...>'代码,重点看文件开头、结尾以及注释隐藏的内容。
  • 插件排查:一次性禁用所有插件,测试站点是否还会跳转。如果恢复正常,逐个启用插件,定位出导致跳转的问题插件并删除。
  • wp-config.php检查:查看该文件是否被篡改,比如WP_HOME、WP_SITEURL被修改为恶意站点,或者文件末尾被添加陌生代码段。
  • .htaccess文件检查:备份当前.htaccess后,清空内容,替换为WordPress默认规则:
    # BEGIN WordPress
    <IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteBase /
    RewriteRule ^index\.php$ - [L]
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule . /index.php [L]
    </IfModule>
    # END WordPress
    
    替换后测试站点是否恢复正常。

2. 服务器层面排查

  • 站点返回头显示服务器为LiteSpeed,可能存在服务器端的恶意配置:
    • 联系主机商,检查虚拟主机的重定向设置、CDN缓存规则(若使用CDN)是否被篡改。
    • 排查服务器上是否存在恶意脚本或未授权的配置修改,比如全局PHP配置文件、服务器级别的.htaccess文件。

3. 恶意软件扫描

  • 使用WordPress安全插件(如Wordfence、Sucuri SiteCheck)对站点进行全面扫描,检测被篡改的文件、后门程序和恶意代码,按照插件提示清理威胁。

4. 修复文件权限

  • 设置正确的文件权限:目录权限设为755,文件权限设为644,防止恶意脚本被写入或执行。

5. 重新安装WordPress核心文件

  • 在WordPress后台的「仪表盘」→「更新」页面,点击「重新安装WordPress」,替换被篡改的核心文件(此操作不会删除内容、主题和插件)。

内容的提问来源于stack exchange,提问作者Tony M. Gibson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 05:18:11