Skip to content
All articles
July 11, 2026·4 min read

My WordPress site got hacked and shows gambling/pharma ads — what now?

A practical, step-by-step guide: how to clean an infected WordPress site that redirects to gambling or pharma spam, and how to secure it so it stays clean.

You open your business website and instead of your homepage, a casino ad appears. Or clients message you saying that when they visit on their phone, they get sent to a betting or pharmacy site. It's a horrible feeling, and the first instinct is panic. The good news: in most cases it can be cleaned, and your site can fully recover.

This kind of attack isn't personal. Automated bots scan the internet non-stop and get in through outdated plugins, weak passwords, or compromised hosting accounts. Once inside, they inject code that redirects visitors or displays hidden ads. Below are the concrete steps, in the order that matters, so you can limit the damage, clean the infection, and make sure it doesn't come back.

First steps: stop the bleeding, don't rush to delete

Before anything else, take a few minutes and do things in order. Panic pushes you to delete files at random and lose evidence.

  • Put the site in maintenance mode or take it offline temporarily, so visitors stop getting redirected and browsers don't flag it as dangerous.
  • Change passwords immediately: the hosting account, cPanel/control panel, the database, FTP/SFTP, and every WordPress admin user.
  • Make a full backup of the CURRENT state (files + database), even though it's infected. You need it as evidence and as a safety net.
  • Don't immediately "restore" an old backup without knowing WHEN you were hacked — you risk restoring the infection too, or losing recent orders and data.

If you have customers who buy through the site, tell them briefly and honestly that you're working on a technical issue. Transparency helps more than silence.

What the infection looks like and where it hides

Redirects to gambling or pharma almost always come from injected code. So you know what to look for, here are the classic spots:

  • Core files that should be clean: index.php, wp-config.php, .htaccess, and the active theme's files (especially header.php and footer.php).
  • Hidden code starting with functions like eval, base64_decode, or long unreadable strings — the typical sign of a backdoor.
  • A "nulled" (pirated) plugin or theme, downloaded free from a shady site. It's the most common way in.
  • Admin users you didn't create. Check the user list in WordPress.
  • Scheduled tasks (cron) or new files that recently appeared in wp-content/uploads, where PHP code has no business being.

One important detail: many attacks show the ad ONLY to visitors coming from Google or on mobile, not to you when you're logged in. That's why it seems "fine for you" while clients see something else.

The actual cleanup, step by step

Once you have a backup and changed passwords, move to cleaning. Order matters:

  • Run a serious security scanner (for example Wordfence or MalCare) that compares your files against the original WordPress versions and shows you exactly what was modified.
  • Reinstall the WordPress core and theme fresh, from official sources, to overwrite the infected files.
  • Delete any plugin or theme you don't use — especially pirated or unknown ones.
  • Clean the database of injected scripts (spam links, redirects in options). It's easy to break something here, so work on a copy.
  • Regenerate the "salt keys" in wp-config.php to log out any stolen session.

If at any step you're unsure what you're deleting, stop. One wrong file deleted can take down the whole site. That's the moment a person with experience is worth more than another random tutorial.

After cleanup: secure it so it doesn't repeat

Cleaning without securing means you're hacked again in a few weeks. Here's how you close the doors:

  • Keep WordPress, the theme, and plugins always up to date. Most hacks exploit old versions with holes that are already public.
  • Drop every pirated or unused plugin. Each extra plugin is one more door.
  • Long, unique passwords for every account, plus two-factor authentication (2FA) for admin.
  • A firewall/security plugin that blocks brute-force attacks and limits login attempts.
  • Automated backups, kept off the server, so you always have a clean version to return to.

Honestly: if the theme or site was built on pirated plugins or old, fragile code, sometimes it's cheaper and safer to rebuild clean than to keep patching. That's a math decision, not a matter of pride.

How we can help (MPO Web Studio)

We build and maintain websites for local businesses across the whole country, fully remote — it doesn't matter if you're in Cluj, Bucharest, or a village in Cluj-Napoca.

If you have a hacked WordPress site, we can check it, clean it, and secure it, then tell you honestly whether it's worth saving or rebuilding. We don't sell fear: if it's a quick fix, we'll tell you exactly that.

For those who keep fighting WordPress and plugins, we also have another path: we prepare a free demo of your new site BEFORE you pay anything, so you see the result before you decide. Transparent pricing, no surprises.

If you'd like a human set of eyes on your situation, message us on WhatsApp with your site's address and a short description of what you see. We'll look and tell you honestly which is the fastest road to a clean, safe site.

Frequently asked questions

How long does it take to clean a hacked site?+

It depends on how deep the infection went. A simple case, with a single injected file and a good backup, can be fixed in a few hours. If there are multiple backdoors, an affected database, and several compromised plugins, it can take one or two days of careful work. What matters isn't speed, it's leaving no backdoor behind.

My site shows up in Google with a "this site may be dangerous" warning. What do I do?+

First, clean the infection completely. Then, from Google Search Console, request a review through the security issues section. Google rescans the site and, if it's clean, removes the warning within a few days. Don't request the review before you're sure it's clean — a rejection sets you back.

Can I lose customer data or orders during cleanup?+

If you work correctly, no. That's why the first step is a full backup of the current state, even infected. Cleanup is done on a copy, and the database is touched carefully. The risk of loss appears when someone deletes in a panic or blindly restores a very old backup over recent data.

Why was my site hacked? There's nothing important on it.+

You weren't chosen personally. Automated bots hunt for any vulnerable site to use for spam, redirects, and ads — it doesn't matter how small you are. A small site with old plugins and weak passwords is exactly what they want: easy to break into and easy to use.

Is it better to repair or rebuild the site from scratch?+

It depends on its state. If it's a well-built, up-to-date site with a single incident, repairing and securing it is the fastest road. If it ran on pirated plugins, old code, and had already been hacked once, it's often cheaper long-term to rebuild it clean. An honest audit tells you which option is real for you.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
Free · no obligation

Want to see what your business's website could look like?

Message us on WhatsApp and we'll prepare a FREE demo website with your business name. See it first — decide after.

Request a free demo websiteWe reply on WhatsApp within minutes