WordPress站点出现未知管理员用户、wp-cleansong插件及页面跳转问题的解决求助
WordPress站点出现未知管理员用户、wp-cleansong插件及页面跳转问题的解决求助
Hey there, sorry to hear your WordPress site got hit by this nasty compromise—let’s walk through fixing this step by step, nice and methodically:
1. Secure your access first (critical!)
- Change your admin password immediately: Use a long, unique mix of letters, numbers, and symbols. If your site supports two-factor authentication (2FA), turn it on right away—it adds a huge extra layer of protection.
- Remove the unknown admin account:
- Log into your site’s database via phpMyAdmin (most hosting providers include this in their control panel).
- Find the
wp_userstable (your prefix might be different if you changed it during setup). - Locate the suspicious admin user, delete it, then head to the
wp_usermetatable and erase all meta entries linked to that user’s ID to avoid leftover junk.
2. Delete the malicious wp-cleansong plugin (and any other weird ones)
- Don’t use the WordPress dashboard to delete it—there’s a chance the dashboard itself is tampered with. Instead:
- Access your site files via FTP or your hosting provider’s file manager.
- Navigate to
wp-content/plugins/, find thewp-cleansongfolder, and delete the entire directory. - Scan through the plugins list for any others you don’t recognize or remember installing—nuke those too.
3. Fix the redirect issue
- Check core WordPress settings: If you can still access the dashboard, go to Settings → General. Make sure both "WordPress Address (URL)" and "Site Address (URL)" are set to your correct domain. If they’re altered, switch them back.
- Clean up your .htaccess file:
- Find the
.htaccessfile in your site’s root directory. - Delete any suspicious rewrite rules or code that forces redirects to random sites.
- Replace it with the default WordPress .htaccess code if needed:
# BEGIN WordPress <IfModule mod_rewrite.c> RewriteEngine On RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> # END WordPress - Find the
- Scan theme files for bad code: Open your active theme’s
functions.php,header.php, andfooter.phpfiles. Look for sketchy snippets likeeval(),base64_decode(), or any redirect functions you don’t recognize. Delete that code, or restore the theme from a clean backup if you have one.
4. Repair and harden your site
- Verify WordPress core files: Download a fresh copy of the exact WordPress version your site uses from the official source. Replace the
wp-adminandwp-includesfolders with the fresh ones (don’t touchwp-contentorwp-config.php—those hold your unique content and settings). - Check for hidden backdoors: Scan the
wp-content/uploadsdirectory for random PHP files you didn’t upload—hackers often drop backdoors here. Delete any suspicious files you find. - Audit user permissions: Go to Users → All Users in your dashboard. Make sure only trusted accounts have Administrator access. Demote or delete any other accounts you don’t recognize.
5. Lock down your site to prevent future attacks
- Install a reputable security plugin: Tools like Wordfence or iThemes Security (downloaded directly from the WordPress plugin repository) can scan for malware, block brute-force attacks, and monitor site changes.
- Keep everything updated: Regularly update WordPress core, themes, and plugins—outdated software is one of the most common entry points for hackers.
- Restrict admin access: If possible, limit access to your
wp-adminarea to only specific IP addresses (you can set this up via .htaccess or your hosting control panel). You can also change the default login URL to make it harder for bots to find. - Backup regularly: Schedule automatic backups of your site files and database. Store backups off-site (like cloud storage) so you can quickly restore if another attack happens.
备注:内容来源于stack exchange,提问作者gabriele Balli
相关产品推荐
相关产品推荐

