Close Menu
WordPress ExpertsWordPress Experts
    Facebook
    WordPress ExpertsWordPress Experts
    • Technology
      • AI & Machine Learning
      • Cloud Computing
      • Cybersecurity
      • Software Reviews
    • CRM
      • Freshworks
      • HubSpot
      • Microsoft Dynamics
      • Open Source CRM
      • Salesforce
      • Zoho
    • Programming
      • WordPress
        • WordPress Errors
        • WordPress Themes
        • WordPress Performance
        • WordPress Plugins
        • WordPress SEO
          • Google AdSense
        • Vulnerabilities
        • Responsive WordPress Themes
        • WooCommerce
          • WooCommerce Tips
        • WordPress Security
          • Wordfence
    • Web Development
    • Web Hosting
    • Digital Marketing
    • Contacts
      • Write for Us
      • Fix Hacked WordPress Site
      • Web Design Services
      • Page Builder Services
      • Woocommerce Services
      • WordPress Forms Services
      • WordPress LMS Development Services
      • WordPress Maintenance & Support Services
    Facebook
    WordPress ExpertsWordPress Experts
    Home»Programming»WordPress»How to Fix the WordPress Redirect Hack (The 2026 Guide)
    WordPress

    How to Fix the WordPress Redirect Hack (The 2026 Guide)

    WP Experts TeamBy WP Experts TeamJanuary 9, 2026Updated:January 9, 2026No Comments5 Mins Read
    Share Facebook Twitter LinkedIn Reddit Telegram Email WhatsApp
    FIX WORDPRESS HACK REDIRECT
    Share
    Facebook Twitter LinkedIn Email Telegram WhatsApp

    You click on your website. You expect to see your homepage.

    Instead, the screen flashes white, and suddenly you are looking at a strange website selling illegal medicine, gambling, or adult content.

    This is called the WordPress Redirect Hack.

    It is one of the most dangerous hacks because it steals your traffic. Even worse, it destroys your reputation with Google. If Google sees your site redirecting users to spam, they will blacklist you immediately.

    In this guide, we will show you exactly how to find the malicious code and remove it—even if you can’t log in to your dashboard.

    How the Redirect Hack Works

    Hackers are smart. They rarely change your homepage directly because you would notice that. Instead, they use “cloaking” tactics.

    The “Mobile Only” Trick: Often, the hacker sets the virus to only redirect visitors on mobile phones. If you check your site on your laptop, it looks fine. This tricks you into thinking your site is safe while your mobile customers are being sent to spam sites.

    The “Google Search” Trick: The virus checks where the visitor came from.

    • If you type yoursite.com directly -> No Redirect.

    • If you click a link from Google -> Redirect to Spam.

    This keeps the admin (you) in the dark while stealing all your SEO traffic.

    Step-by-Step Removal Guide

    We will start with the most common hiding spots for redirect malware. You will need to use FTP (File Transfer Protocol) or the File Manager in your hosting control panel.

    Step 1: Check the .htaccess File (The Usual Suspect)

    The .htaccess file controls traffic on your site. Hackers love to modify this file to force redirects.

    1. Connect via FTP: Access your site’s root folder (usually public_html).

    2. Find the File: Look for .htaccess.

    3. Edit: Right-click and view the file.

    4. Look for Suspicious Code:

      • A clean WordPress .htaccess file is usually short (about 10-15 lines).

      • If you see hundreds of lines of random letters or code referencing “HTTP_USER_AGENT” or “HTTP_REFERER,” this is the virus.

    5. The Fix: Delete the .htaccess file entirely. Then, log in to your WordPress Dashboard, go to Settings > Permalinks, and click “Save.” WordPress will create a fresh, clean file for you.

    Step 2: Check wp-config.php and index.php

    These are core system files. They should rarely change.

    1. Open index.php in your root folder. It should be very short. If you see a wall of code at the top that looks like scrambled letters (eval(base64_decode...)), delete it.

    2. Check wp-config.php. Hackers often hide a “include” script here that loads the virus from a temporary file.

    Step 3: The “Header” Injection

    Hackers often inject JavaScript into your theme’s header to redirect users.

    1. Go to wp-content/themes/your-theme/.

    2. Open header.php.

    3. Look for <script> tags that link to strange domains. If you see code that looks like window.location.replace, delete it.

    Step 4: Check the Database (The Deep Hiding Spot)

    Sometimes the redirect is not in a file, but in your database settings.

    1. Open phpMyAdmin from your hosting dashboard.

    2. Go to the wp_options table.

    3. Check the siteurl and home rows.

    4. Make sure the URL is actually your website (e.g., https://yoursite.com). If it points to a spam site, change it back immediately.

    The "Nuclear" Option (Core Replacement)

    If you checked the files above and the redirect is still happening, the virus is hiding deep in your system files. The best way to fix this is to replace all WordPress core files.

    How to do it safely:

    1. Download WordPress: Get a fresh zip file from WordPress.org.

    2. Extract the Zip: Unzip the folder on your computer.

    3. Upload: Connect to your server via FTP. Upload the wp-admin and wp-includes folders from your computer to your server, overwriting the old ones.

      • Note: This replaces the infected system files with clean ones. It does not touch your content (images/posts) or configuration.

    Fixing Your SEO (Google Blacklist)

    Once the redirect is gone, you have one more big problem. Google likely marked your site as “Deceptive.” You need to clear your name.

    1. Google Search Console: Log in and check the “Security Issues” tab.

    2. Request Review: Click the button to tell Google you have cleaned the site.

      • What to say: “I identified a malicious redirect in my .htaccess file. I have removed the code, replaced core WordPress files, and updated all passwords. The site is now clean.”

    3. Wait: It usually takes 24-72 hours for Google to remove the red warning screen.

    Prevention (Lock the Doors)

    Don’t let this happen again.

    1. Change Passwords: Hackers might still have your password. Change your Admin, FTP, and Database passwords now.

    2. Disable File Editing: Stop hackers from editing your theme files from the dashboard. Add this line to your wp-config.php:

      PHP
       
      define( 'DISALLOW_FILE_EDIT', true );
      
    3. Install a Firewall: Use a plugin like Wordfence or a service like Cloudflare to block hackers before they even reach your site.

    Conclusion

    The “Redirect Hack” is scary, but it is just code. It can be deleted.

    Checklist to Fix It:

    1. Check .htaccess first (it’s usually there!).

    2. Replace wp-admin and wp-includes with fresh copies.

    3. Check your database URLs.

    4. Tell Google you are clean.

    Need Help Cleaning Up? If you are uncomfortable deleting server files or can’t find the malicious code, do not risk breaking your site further. Contact Our Malware Removal Team. We can scan your site, find the hidden redirect, and clean it up today.

    For more help, you can check the Google Webmasters Hacked Site Guide

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp
    Previous ArticleHow to Fix the “Too Many Redirects” Error in WordPress (The Complete 2026 Guide)
    Next Article How to Fix 503 Service Unavailable Error in WordPress (The 2026 Guide)
    WP Experts Team
    • Website

    As a global digital solutions partner, we empower businesses with integrated technology platforms. We specialize in crafting high-performance WordPress websites—from custom design and SEO-optimized content to robust e-commerce. Furthermore, we unlock growth by implementing and optimizing Salesforce, streamlining your CRM, and automating sales and service processes. From your digital storefront to your customer relationships, we provide end-to-end solutions to achieve your online goals.

    Related Posts

    WordPress Plugins

    Elementor Pro WordPress Plugin free download v3.35.0

    February 5, 2026
    WooCommerce

    Add Custom Fields to WooCommerce Registration Without Coding

    February 4, 2026
    WordPress Errors

    How to fix image upload issue in WordPress

    January 30, 2026
    Add A Comment

    Comments are closed.

    fix hacked wordpress websites and remove malware
    fix wordpress issues
    create a wordpress website with elementor
    fix woocommerce issues and customize theme
    migrate or clone wordpress site to new host or domain
    Top Articles

    Elementor Pro WordPress Plugin free download v3.35.0

    February 5, 2026

    Add Custom Fields to WooCommerce Registration Without Coding

    February 4, 2026

    How to fix image upload issue in WordPress

    January 30, 2026

    How to Fix WordPress Login Page Refreshing and Redirecting Issue (2026 Complete Guide)

    January 28, 2026
    Facebook
    • Client Experiences
    • WordPress Forms Services
    • Page Builder Services
    • Woocommerce Services
    • WordPress Migration Services
    • WordPress Maintenance & Support Services
    • Fix Hacked WordPress Site
    • WordPress LMS Development Services
    • Web Design Services
    © 2026 WordPress Experts All rights reserved

    Type above and press Enter to search. Press Esc to cancel.