Rank on Gemini and Chatgpt
Vicky.Dev
  • Tutorials
  • Tech
  • Camera & Photography
  • Themes
  • Plugins
  • SEO
  • Free Tools
  • Misc
  • Contact Me
No Result
View All Result
  • Tutorials
  • Tech
  • Camera & Photography
  • Themes
  • Plugins
  • SEO
  • Free Tools
  • Misc
  • Contact Me
No Result
View All Result
Vicky.Dev
No Result
View All Result

WordPress Redirect Hack: Find and Fix It Permanently (2026)

Vicky Bhandari by Vicky Bhandari
August 22, 2026
in WordPress Security
0
WordPress Redirect Hack

If your WordPress site redirects visitors to spam, pharmacy, or casino sites, your site has been hacked. This is commonly called a WordPress Redirect Hack. Attackers use it to steal your visitors and send them to their own spammy sites.

Someone injected malicious code into your theme, a plugin, or your database. This guide shows you where the code hides and how to remove it safely.

Table of Contents

Toggle
  • Why Your WordPress Site Redirects to Another Website
  • Signs Your Site Has a Redirect Hack
  • Where to Look First: The .htaccess File
  • Checking wp-config.php and functions.php for Malicious Code
  • Check Cron Jobs and the Uploads Folder Too
  • Malicious or Backdoored Plugins
  • How to Fix a WordPress Redirect Hack
  • How to Stop WordPress Redirect Hack From Happening Again
  • Frequently Asked Questions About WordPress Redirect Hack
    • 1. Why does my WordPress site redirect to another website? 
    • 2. How do I remove a WordPress redirect virus?
    • 3. Why does wp-admin redirect to spam?
    • 4. Can a redirect hack come back after I clean it?

Why Your WordPress Site Redirects to Another Website

A redirect hack occurs when an attacker gains access to your site and adds code that redirects visitors elsewhere. This usually happens through an outdated plugin, a weak admin password, or a vulnerable theme.

The attacker’s goal is simple. They want traffic for their own spam or scam sites. Your site becomes the delivery vehicle. Google notices this fast, and your rankings drop.

The code can hide in several places. The most common spots are your .htaccess file, your wp-config.php file, your theme’s functions.php file, or a plugin that looks legitimate but isn’t.

Signs Your Site Has a Redirect Hack

Watch for these patterns:

  • Mobile visitors get redirected, but the site looks normal on desktop
  • Google Search Console shows a “This site may be hacked” warning
  • Visitors land on pharmacy, casino, or adult content sites instead of your pages
  • The redirect only happens on the first visit, not on repeat visits
  • Your site loads fine when you check it, but users report redirects
  • Search results show strange titles or descriptions that you never wrote

Attackers often target first-time visitors or mobile users on purpose. This makes the hack harder to catch, since you, as the site owner, rarely match that pattern when you check your own site.

Where to Look First: The .htaccess File

Your .htaccess file controls how your server handles requests. It is one of the easiest places for attackers to hide a redirect, and it is the first place you should check.

Connect to your server through FTP or your hosting file manager. Open the .htaccess file in your site’s root folder.

A normal WordPress .htaccess file looks clean and short. It has a block that starts with # BEGIN WordPress and ends with # END WordPress. Anything outside that block should get your attention, especially rules that mention RewriteCond, RewriteRule, or long strings of random characters.

Malicious redirect rules often check the visitor’s user agent or referrer before redirecting. This is exactly why the hack only shows up for some visitors and not others.

If you find code you don’t recognize and can’t explain, remove it. Keep a backup of the file before you make changes, in case you need to compare later.

Checking wp-config.php and functions.php for Malicious Code

These two files are common hiding spots because they load on every page request.

Open wp-config.php and look for code near the top or bottom of the file that doesn’t belong there. Malicious code here often uses functions like eval, base64_decode, or gzinflate to hide what it actually does. Legitimate WordPress code rarely uses these functions together in this way.

Do the same check in your active theme’s functions.php file. Look for redirect logic that checks conditions like the visitor’s device type or where they came from before sending them elsewhere.

If you’re not confident reading PHP, copy the suspicious code into a text file and compare it against a fresh copy of the same file from an unmodified WordPress installation or theme download. Differences will stand out.

Check Cron Jobs and the Uploads Folder Too

Attackers don’t always hide the redirect in a file you’d think to check.

Sometimes the trigger sits inside a scheduled task instead. Check your WordPress cron jobs (wp_cron) and any server-level cron jobs on your hosting panel. A hidden scheduled task can re-add malicious code even after you clean the files, which makes the hack look like it keeps coming back.

Also check your uploads folder at wp-content/uploads. This folder should only hold images and media files, not PHP code. Attackers sometimes drop a PHP file here, disguised as an image, since many servers mistakenly allow PHP to run in this folder. If you find any .php file in your uploads folder, remove it and update your server configuration to block PHP execution there.

One quick way to spot injected files across your whole site: sort your files by last modified date. Anything changed recently that you didn’t touch yourself is worth a closer look.

Malicious or Backdoored Plugins

Sometimes the attacker doesn’t touch your existing files. Instead, they install a new plugin that looks harmless but contains the redirect code.

Check your plugins list in wp-admin. Look for anything you don’t remember installing, or plugins with generic names that don’t match their supposed function.

If your admin panel itself seems compromised or you can’t log in, check the wp_options table directly through phpMyAdmin. Look at the active_plugins entry to see what’s actually running, since this bypasses anything an attacker may have hidden from the admin view.

Delete any plugin you don’t recognize. If you’re unsure whether a plugin is safe, deactivate it first and monitor the site before you delete it completely.

How to Fix a WordPress Redirect Hack

Follow these steps in order.

  1. Back up your site first. Even a hacked site is easier to work with when you have a copy to fall back on.
  2. Put the site in maintenance mode. This stops new visitors from hitting the redirect while you work.
  3. Remove the malicious code from .htaccess, wp-config.php, functions.php, and any backdoored plugins you found.
  4. Reset every password. Change your WordPress admin password, your hosting password, your database password, and your FTP password.
  5. Regenerate your WordPress security keys and salts. You can generate new ones from the WordPress secret key generator and paste them into wp-config.php. This logs out anyone with a stolen session.
  6. Scan the full site with a security plugin like Wordfence or Sucuri to catch anything you missed.
  7. Update WordPress core, your theme, and all plugins to the latest versions.
  8. Clear your cache and CDN. If you use Cloudflare or any caching plugin, a cached version of the redirect can keep serving to visitors even after you remove the code. Clear it fully before you consider the site clean.
  9. Check other sites on the same server. If your hosting or droplet runs multiple WordPress sites, one infected site can reinfect the others. Check each site for the same signs before you close this out.
  10. Request a review in Google Search Console once the site is clean. This tells Google to remove the hacked site warning.

How to Stop WordPress Redirect Hack From Happening Again

Cleaning the hack is only half the job. Without changes, the same vulnerability lets the attacker back in.

  • Keep WordPress core, themes, and plugins updated at all times
  • Remove any plugin or theme you’re not actively using
  • Use a strong, unique password for your admin account and enable two-factor authentication
  • Limit login attempts to block brute force attacks
  • Set up file integrity monitoring so you get alerted the moment a core file changes
  • Avoid nulled or pirated themes and plugins, since these are a common entry point for backdoors

If this feels like more than you want to handle yourself, this is exactly the kind of cleanup we handle as a fixed scope service. You send us access, we find the injected code, remove it, and harden the site so it doesn’t come back.

Frequently Asked Questions About WordPress Redirect Hack

1. Why does my WordPress site redirect to another website? 

An attacker has injected malicious code into your site, usually through an outdated plugin or theme, a weak password, or a known vulnerability. The code redirects visitors to a spam or scam site instead of your own pages.

2. How do I remove a WordPress redirect virus?

Check your .htaccess file, wp-config.php, your theme’s functions.php file, and your installed plugins for code you don’t recognize. Remove it, reset all your passwords, and scan the site with a security plugin to confirm it’s clean.

3. Why does wp-admin redirect to spam?

This usually means the hack has reached deeper into your site, often through a compromised admin account or a backdoored plugin that intercepts admin requests. Check your active plugins list and your database directly, since the admin panel itself may be showing you incomplete information.

4. Can a redirect hack come back after I clean it?

Yes, if the original vulnerability isn’t fixed. Simply removing the malicious code without updating software, changing passwords, and removing the entry point means the attacker can inject the same code again.

Previous Post

WordPress Pharma Hack: How to Find It, Clean It Permanently

Next Post

Scalable Cloud Architecture for Fintech Applications Powered by Crypto VPS

Next Post
Scalable Cloud Architecture for Fintech

Scalable Cloud Architecture for Fintech Applications Powered by Crypto VPS

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • AI
  • App Development
  • Browser Games
  • Business and Productivity
  • Camera & Photography
  • Hosting
  • MacOS
  • Misc
  • Plugins
  • SaaS & Startups
  • SEO
  • Tech
  • Themes
  • Troubleshooting / Fixes
  • Tutorials
  • Web Development
  • WordPress Development
  • WordPress Security
  • World
Choosing a Motion Workflow for an Owned Illustration on a Website

Choosing a Motion Workflow for an Owned Illustration on a Website

October 4, 2026
DME and HME Software Platforms for Medical Equipment Providers

10 DME and HME Software Platforms for Medical Equipment Providers

October 2, 2026
How to Get Your Anthropic API Key

How to Get Anthropic API Key (2026 Guide)

September 24, 2026

Helpful Links

  • Write For Us
  • Contact Me
  • Privacy Policy
  • About
  • Cancellations, Returns & Refunds
  • Terms and Conditions

© 2026 Vicky Bhandari. All Rights Reserved.

No Result
View All Result
  • Tutorials
  • Tech
  • Camera & Photography
  • Themes
  • Plugins
  • SEO
  • Free Tools
  • Misc
  • Contact Me

© 2026 Vicky Bhandari. All Rights Reserved.