Learn / Troubleshooting / Security and access
Security and access
Site is hacked or redirects to spam
Usually: Outdated software, stolen passwords, a vulnerable plugin or a pirated theme.
- Take the site offline or into maintenance mode if you can.
- Restore from a clean backup taken before the infection.
- Update everything and delete unused plugins and themes.
- Change all passwords, including hosting, database and FTP.
- Scan for backdoors and unknown admin users.
Cannot log in to WordPress admin
Usually: Wrong credentials, a security plugin lock, a redirect loop, or a corrupted session.
- Reset the password through the database or WP-CLI.
- Disable security plugins by renaming their folder.
- Clear cookies for the site.
Locked out after too many login attempts
Usually: A security plugin or the host's firewall blocked your address.
- Wait for the lock to expire.
- Ask the host to unblock your IP.
- Rename the security plugin's folder over SFTP to disable it temporarily.
Unknown admin users have appeared
Usually: A compromise, or a plugin that creates accounts.
- Treat as a hack: back up, then remove the users.
- Change all passwords and keys.
- Scan for backdoors and review recently changed files.
Google warns that the site contains malware
Usually: The site was compromised and injects malicious content into pages.
- Clean the site and update everything.
- Request a review in the search console after cleaning.
- Check for hidden files and database injections.
I lost the phone with my authenticator app
Usually: Two-factor codes are no longer available.
- Use backup codes if you saved them.
- Contact the provider's recovery process with proof of identity.
- In future, store backup codes safely and register a second device.