Description
WordPress Incident Response — Compromised Site Cleanup & Secure Rebuild I run a WordPress site on a self-managed Ubuntu VPS (Apache, PHP 8.x, MySQL) that has been compromised. I need an experienced security specialist to contain it, rebuild it clean, and make sure it stays clean. Current situation: Site front-end returns a blank page (malware fatals during page load); wp-admin remains accessible Confirmed webshell/loader files planted in core directories, fake plugin and theme folders acting as droppers, and a malicious must-use plugin Malware files are owned by the web server user and regenerate automatically after deletion, indicating database-resident persistence Restoring a 3-month-old snapshot did not resolve it — the infection returned, suggesting the compromise predates the snapshot Server previously had root SSH access via password authentication; unrecognized administrator accounts exist in the WordPress user table Likely initial vector: a known-vulnerable file manager plugin (unauthenticated RCE) Scope of work: Containment and triage of the current environment Forensic identification of the persistence mechanism and initial entry vector Clean rebuild on fresh infrastructure — new instance, current WordPress core, plugins/themes reinstalled from official sources only Selective content migration (posts, pages, media, verified user accounts) without carrying the infected database wholesale; audit and clean the user table, options table, and scheduled tasks Credential r