Hacked skincare sites that kept getting reinfected
Malware removal
The problem
These sites belong to the same client we built a skincare website and quiz for, and are part of the wider cleanup across the client’s sites.
A UK skincare site had been cleaned of malware more than once, but the infection kept coming back. By the time we looked at it, the host had rate-limited the whole site, so every page was blocked, even robots.txt. Several images were missing, and pages had disappeared from the menu.
What we found
Instead of deleting the malware files again, Abner went through the server access logs and the site’s own activity log.
- The way in was ordinary. The attacker logged in through the normal WordPress login with a valid administrator password, then uploaded a fake plugin disguised as a security tool.
- The real backdoor was hidden one level deeper. The attacker had created WordPress Application Passwords, named to look like an SEO tool. They kept full access to the site even after the password was changed, and they skip two-factor login entirely. No earlier cleanup had closed them.
- The likely first entry point was an outdated page builder plugin with a known flaw that lets attackers create admin accounts.
What we did
- Removed the malware, reset the administrator password, rotated the site’s security keys and revoked the hidden Application Passwords.
- Checked everything beyond the files: the database options table, scheduled tasks, drop-in files and configuration.
- Updated the outdated plugin.
- Verified the site against the official WordPress file checksums.
Recovering the lost content
The missing pages had been removed when old user accounts were deleted in a previous cleanup, because deleting a WordPress user also deletes what they wrote. Abner found them still in the Trash and restored all of them, 14 pages and 10 blog posts, with their original IDs, which repaired the menu by itself. The missing images were recovered from the public web archive and the site’s own image cache.
The second site
A second site run by the same team had been hacked in the same minute, which almost always means one shared way in. The same log checks confirmed it: administrator logins from a single source, switching browser signatures within seconds, all with a valid password. One admin account was reused across the sites, so one leaked password opened all of them. The same hidden Application Passwords were there too. We closed them, reset the password, rotated the keys and verified the site.
The result
Both sites are clean and closed at the shared source, not one at a time. The lost pages and posts are back and the menu works. The owner got a plain-language explanation of how the break-in happened, and the two steps that stop it happening again: a unique admin password for each site, and two-factor login.
The honest note
This was real client work, so the client and the sites are not named. The diagram on this page shows the work, not the client’s sites.