wp2shell Unauthenticated RCE in WordPress core (CVE-2026-63030), affecting 6.9–7.0.1. Update to 7.0.2 or 6.9.5 now. A stock install is enough, plugins aren't required. Site already compromised? Start here →
Sentrax Report a compromise

Incident response

Your website's been hacked. Here's what to do next

If your site has been compromised, or you think it has, the next hour matters more than the last week. This is the calm, ordered version of what to do, and how we can help you.

The first hour

A calm, ordered response

Work top to bottom. The order matters: acting out of sequence, especially deleting things early, is how evidence and options get lost.

1

Don't destroy evidence

Resist the urge to delete files, reinstall, or "clean it up" straight away. That erases the trail that shows how they got in and what they touched, and it rarely removes the backdoor. Slow is smooth here.

2

Contain it

Take the site into maintenance mode or offline, rotate every credential the site can reach (hosting, admin, database, API keys, mail), and if you're on shared hosting, isolate it from your other sites. Do it quietly, without announcing it to whoever's inside.

3

Preserve what happened

Before you change anything, take a snapshot of the site and server and pull the logs, web server, application, and hosting. This is the single most valuable thing you can do, and the thing most often skipped. It's what lets anyone reconstruct the incident later.

4

Work out what happened

Identify how they got in, what they left behind (backdoors, injected scripts, rogue admin accounts), and what they reached, including any customer or personal data. What your site is serving to visitors right now is part of this, and it's something we can tell you quickly.

5

Eradicate and recover

Fix the root cause first, patching the actual entry point, then remove the backdoors and rebuild from a known-good state. Restoring a backup without closing the entry point just resets the clock until the next visit.

6

Harden and watch

Close the exposure, tighten access, and put monitoring in place. Attackers come back to sites that paid off once, so the days after recovery are when reinfection shows up. This is where ongoing detection earns its place.

Avoid these

What not to do

The common mistakes that turn a contained incident into a repeat one.

×Deleting the suspicious files and assuming it's over. Backdoors are designed to survive that.
×Wiping or reimaging before you've preserved a snapshot and the logs.
×Restoring an old backup without fixing how they got in, or the backup may already be compromised.
×Assuming disabling plugins fixes a core flaw. Compromised plugins live in WordPress core so only patching and remediation removes the infection.
×Paying anyone demanding money to "release" your site before you've taken advice.
×Ignoring the data question. If personal information was exposed, you may have notification obligations, get advice early.

Get help

Take it off your hands

Send us the site and what you're seeing. We'll assess what's exposed from the outside and tell you plainly where you stand. If you want it handled end to end, we run paid incident-response engagements through DFIR Labs Australia, evidence preservation, eradication, and hardening included.

Leave a phone number and the best way to reach you if it's live right now, and we'll prioritise accordingly.

Submitting this form is not a guarantee of a response time.

Straight answers

Common questions

Can you tell if I'm still compromised?

Often, yes. We can see what your site is serving to visitors and whether it's still behaving maliciously, from the outside, without touching your server. That's usually the fastest way to know if a clean-up actually worked.

Should I just restore a backup?

Only after the entry point is closed, and only if the backup predates the compromise. Restoring over an unpatched flaw, or restoring an already-infected backup, just resets the clock. Preserve first, patch the root cause, then recover.

I'm on WordPress and heard about wp2shell. Am I affected?

If you're running WordPress core 6.9 through 7.0.1 and haven't updated, treat yourself as exposed, it needs no plugins and no login. Update to 7.0.2 (or 6.9.5 on the 6.9 branch) immediately, then check for signs you were already hit before the patch. If you're unsure, send it to us.

How much does it cost?

Assessment starts with a conversation and it depends on the functionality of your website. Full incident-response engagements are scoped to the situation and run through DFIR Labs Australia. Use the form and we'll come back with next steps.

Was customer data taken?

That's one of the first things worth establishing, because it can carry notification obligations. We help you work out what was reachable and what the evidence shows, so you can make that call on facts rather than assumptions.