You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

遭黑客攻击后WordPress管理员无法安装更新插件及系统求助

Fixing WordPress Admin Permission Issues Post-Hack

Hey there, sorry to hear you're stuck with this frustrating post-hack problem—let's walk through the most likely fixes to get your admin functionality back up and running.

1. Verify Full Administrator Permissions (Database Check)

Hackers often tamper with user roles to lock you out of critical actions. Here's how to confirm your account has full admin access:

  • Access your site's database via phpMyAdmin or your host's database tool.
  • Navigate to the wp_users table and note the ID of your admin account.
  • Go to the wp_usermeta table (prefix might be different if you changed it) and look for two rows linked to your admin ID:
    • wp_capabilities: The value should be a:1:{s:13:"administrator";b:1;} (this confirms you have admin privileges).
    • wp_user_level: The value should be 10.
  • Also, scan the wp_users table for any unknown admin accounts—hackers often leave backdoor accounts here. Delete any suspicious ones immediately.

2. Reset File & Folder Permissions

Hacked sites frequently have their permissions altered to block modifications. Reset them to WordPress-recommended values:

  • Folders: Set to 755 (read/write/execute for owner, read/execute for group and public).
  • Files: Set to 644 (read/write for owner, read-only for group and public).
  • wp-config.php: Lock this down further to 600 (only owner can read/write).
  • You can do this via FTP/SFTP (right-click files/folders to adjust permissions) or run these SSH commands if you have access:
    chmod -R 755 /path/to/your/wordpress/wp-content/
    chmod -R 644 /path/to/your/wordpress/wp-content/*
    chmod 600 /path/to/your/wordpress/wp-config.php
    

3. Check for Restrictive wp-config.php Settings

Hackers might add lines to disable file modifications. Open your wp-config.php and look for these lines—delete or comment them out if present:

define('DISALLOW_FILE_MODS', true); // Blocks plugin installs/updates
define('DISALLOW_FILE_EDIT', true); // Blocks theme/plugin file editing (less critical but worth checking)

Your existing WP_MEMORY_LIMIT setting is fine, but double-check it's placed before the /* That's all, stop editing! Happy publishing. */ line.

4. Eliminate Malicious Theme/Plugin Residues

Even after cleaning files, compromised themes or plugins might be overriding admin permissions. Test this:

  • Switch your active theme to a default WordPress theme (like Twenty Twenty-Four).
  • Disable all plugins temporarily.
  • Try installing/updating a plugin again. If it works, re-enable plugins one by one to find the compromised one, then delete and replace it with a fresh version from the official repo.

5. Reinstall WordPress Core Files

Hackers often modify core WordPress files to backdoor the site. Reinstalling core ensures you have clean, unmodified files:

  • Download the latest stable WordPress version from wordpress.org.
  • Extract the ZIP file, then delete the wp-content folder from the extracted files (we don't want to overwrite your themes/plugins/uploads).
  • Upload the remaining files/folders to your server, overwriting the existing core files (don't worry—this won't touch your content or settings).

6. Reset .htaccess File

Hacked sites often have malicious rules added to .htaccess that block update requests. Fix this:

  • Back up your current .htaccess file (download it to your computer).
  • Replace it with the default WordPress .htaccess content:
    # BEGIN WordPress
    <IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteBase /
    RewriteRule ^index\.php$ - [L]
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule . /index.php [L]
    </IfModule>
    # END WordPress
    
  • Save the file and test updates again.

7. Check Server-Side Restrictions

If none of the above works, your host might have security measures blocking WordPress updates:

  • Look for ModSecurity rules that could be intercepting update requests—contact your host to whitelist these requests if needed.
  • Verify PHP settings: Ensure allow_url_fopen is enabled (check via phpinfo()) and there's no restrictive open_basedir rule in place.
  • Ask your host if they have any WordPress-specific update blocks enabled.

Post-Fix Recommendations

Once you resolve the issue:

  • Change all admin passwords to strong, unique ones.
  • Enable two-factor authentication for all admin accounts.
  • Install a reputable security plugin (like Wordfence or Sucuri) to scan for future threats and monitor access.
  • Set up regular site backups (both files and database) to recover quickly if another incident occurs.

内容的提问来源于stack exchange,提问作者muck

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:25:35