WordPress Malware Removal Checklist After CVE-2026-87902
If your WordPress site is showing spam pages, strange redirects or PHP files nobody on your team uploaded, you need a plan, not a panic. This WordPress malware removal checklist walks through the ten steps that matter, in the order that matters: contain the damage, find everything the attacker left behind, clean it, and close the door they came in through.
It also covers the part most cleanups miss: how to tell whether the site has been quietly reinfected a week later.
Why a malware removal checklist matters right now
WordPress core has had an unusually busy season. WP Care's summary of the 7.1.2 release counts five core security releases between July 17 and September 22, 2026, and notes that "core has needed attention roughly every two weeks since mid-July."
The latest, WordPress 7.1.2, released on September 22, fixes CVE-2026-87902 (a Common Vulnerabilities and Exposures entry rated critical). WordPress describes it as a flaw where an unauthenticated attacker can, under certain conditions, make page template resolution include a local PHP file outside the active theme, which under specific server and theme conditions could lead to remote code execution (RCE). The fix was backported to every eligible branch back to 4.7.
Attackers did not wait. Patchstack's analysis of CVE-2026-87902 logged the first probing attempt at 11:49 UTC on the day of the patch and the first attempt to write a file to disk a few hours later. By the next day, public scanning tooling was circulating and attack traffic was more than ten times the first evening's level. Patchstack scores the flaw 9.2 on the Common Vulnerability Scoring System (CVSS).
Plugins are still the bigger target. The Hacker News reported on September 16 that a file-upload flaw in the WooCommerce Wholesale Lead Capture plugin (CVE-2026-27540, CVSS 9.8) was being used to plant PHP web shells, with Wordfence blocking more than 100,000 exploit attempts since June 2026. And Patchstack's State of WordPress Security in 2026 report found that 91% of the 11,334 new vulnerabilities disclosed in 2025 were in plugins, with a median of five hours to mass exploitation for heavily exploited bugs.
The common thread is a PHP file written to disk. Once that happens, updating WordPress closes the hole but does not remove what came through it. For more background, see our look at last autumn's WordPress mass-exploitation campaigns.
Signs your WordPress site has been hacked
Not every compromise is obvious. Look for any of these:
- Visitors, especially from search or mobile, are redirected to unrelated sites.
- A warning appears in Google Search Console's Security issues report, which flags hacked content, malware and social engineering.
- New PHP files appear in wp-content/uploads, temporary folders or the web root.
- Administrator accounts you do not recognize, or plugins that appear on the server but not in the dashboard.
- Core files such as index.php or wp-blog-header.php are larger or newer than they should be.
- Spam pages in search results, or a sudden jump in outbound email from the server.
The WordPress malware removal checklist: 10 steps
Work through these in order. Skipping ahead, especially straight to "delete the bad file," is how most sites end up infected again.
1. Isolate the site
Put the site into maintenance mode or restrict access to your own IP address so visitors are not served malware while you work. Tell your hosting provider: WordPress.org's official hacked-site FAQ recommends checking whether other sites or services on the same account were affected. Note what you are seeing and when you first saw it; you will need that record later.
2. Back up the infected site
It feels backwards, but take a full copy of files and database before you change anything. Google's web.dev guide to cleaning a hacked site advises making two backups "even though it's still infected," so you can recover content you delete by mistake or start over. Store them off the server and label them clearly as infected.
3. Identify the entry point and the damage
Check your core, plugin and theme versions against recent advisories, and review access logs for the days before you noticed symptoms. For the plugin flaw above, The Hacker News suggests reviewing requests to admin-ajax.php and looking for recently created PHP files, mainly in the uploads directory. Also scan the computers used to manage the site, as WordPress.org recommends, since a compromised laptop can leak new passwords as fast as you set them.
4. Verify core and plugins against official checksums
WordPress.org publishes checksums for every core release and for plugins hosted in its directory. With the WordPress command-line interface (WP-CLI), wp core verify-checksums compares your core files with the official release, and wp plugin verify-checksums --all does the same for directory plugins. Anything modified or unexpected goes on your cleanup list.
Two caveats: premium plugins and themes are not covered, so replace them with fresh copies from the vendor; and extra files in wp-content will not show up in a core check. When you replace core, WordPress.org advises replacing wp-admin and wp-includes over SFTP (SSH File Transfer Protocol) rather than using the dashboard's reinstall option on a compromised site.
5. Remove backdoors, not just the visible malware
A backdoor is any file or code that lets the attacker back in. Search for PHP files where they do not belong (uploads, cache and temporary folders), look for heavily encoded or obfuscated code, and inspect files attackers like to edit, such as index.php, theme header.php, footer.php, functions.php and .htaccess. Check wp-content/mu-plugins too, since must-use plugins load automatically.
Patchstack observed CVE-2026-87902 attempts writing PHP files into server temporary directories, so look outside the WordPress folder as well if your host allows it.
6. Audit users, scheduled tasks and the database
Files are only half the picture. Monarx's June 2026 write-up of a "self-healing" WordPress campaign describes malware that created a rogue administrator, installed a fake plugin that hid itself from the admin screen, stored data in the options table and restored deleted files every six minutes. Delete one file and it came back.
- List every administrator and remove any you cannot account for.
- Review scheduled events (WP-CLI's wp cron event list helps) for hooks that do not belong to a known plugin.
- Compare the plugins folder with the active plugins list in the database.
- Search posts and options for injected scripts and unfamiliar entries.
7. Rotate every credential
WordPress.org's FAQ stresses changing "all access points": FTP or SFTP, wp-admin, your hosting control panel and the MySQL database. Generate new secret keys and salts in wp-config.php, which logs out every existing session, and turn on two-factor authentication. Rotate API keys stored in plugins, too.
8. Patch everything
Update WordPress core, every plugin and every theme, and delete anything you are not using. For CVE-2026-87902, Patchstack lists fixed versions including 7.1.2, 7.0.6, 6.9.9 and 6.8.10. If you cannot update immediately, Patchstack suggests rejecting path traversal sequences in the affected parameter at your firewall or disabling PHP's register_argc_argv setting as a stopgap. Web.dev's key question applies: did you fix the root cause that let the attacker in?
9. Harden the site
- Block PHP execution in wp-content/uploads, a step Monarx also recommends.
- Disable file editing from the dashboard and tighten file permissions.
- Put a web application firewall (WAF) in front of the site.
- Turn on automatic core updates, or schedule a short, regular update window.
- Set up automated, off-server backups that you have tested restoring.
10. Monitor, then request a review
Keep file-integrity and admin-user checks running for at least several weeks. If Google flagged the site, use the Security issues report to request a review only once the whole site is clean; Google says fixing only some pages "will not earn you a partial return to search results." According to web.dev's guidance on requesting a review, malware reviews take a few days, spam-hack reviews can take several weeks, and warnings are removed within 72 hours of approval.
How to tell if your WordPress site is reinfected
Reinfection usually means something from steps 5 to 7 was missed. Watch for these signals in the days after cleanup:
- A file you deleted reappears, or core checksums fail again after a clean pass.
- A new administrator account appears, or an existing one changes email address.
- New PHP files show up in uploads or temporary folders.
- Unfamiliar scheduled events or options return to the database.
- The server makes outbound connections to domains you do not recognize.
- Search Console raises a new security issue.
If any of these happen, go back to step 1 rather than deleting the single file. If your records show a trusted clean backup from before the entry point, restoring it and then repeating steps 7 to 9 is often faster. Automated scanning is making this cycle quicker, as we covered in how agentic AI is changing WordPress exploits.
Where Ðeny WP Pro fits in the checklist
Ðeny WP Pro is a WordPress security plugin built to clean up a hacked site and keep it clean. Most of the checklist maps onto its features:
- Identify and verify (steps 3 and 4): signature and heuristic malware scanning of PHP across wp-content and the web root, with decoding of hidden payloads, plus integrity checks of core and every wordpress.org plugin against official checksums. Known-vulnerability lookup checks your WordPress, plugin and theme versions against the NVD (National Vulnerability Database).
- Remove and repair (step 5): one-click reinstall of tampered files and per-file restore of modified core from the official release, with a full backup and one-click restore available before risky changes.
- Audit (step 6): a database audit surfaces rogue admin users, injected options and posts, and orphaned cron hooks that file scans miss.
- Harden and monitor (steps 9 and 10): a scoring firewall that blocks SQL injection, brute-force logins, scanners and fake search-engine bots, enforced in PHP as well as .htaccess so it holds on nginx; a live traffic monitor; install-time scanning of plugin and theme packages; and a read-only lockdown with a scheduled daily window to install updates and re-lock.
An optional AI review sends flagged files to your own Anthropic API key for a second opinion to cut false positives. Ðeny WP Pro costs $99 per host, including 24 months of updates. Read more in our Ðeny WP Pro launch post.
Clean it once, then keep it clean
The headline vulnerability will change from month to month, but the cleanup does not: contain, back up, verify against checksums, remove every backdoor, audit users and scheduled tasks, rotate credentials, patch, harden and keep watching. The step people skip is the one that brings the malware back.
If you would rather not run this checklist by hand on every site you manage, see how Ðeny WP Pro scans, repairs and locks down WordPress.
Start protecting your funnel today
Put Ðeny to work from day one, and your boss will thank you.

