One of the most common signs of a hacked WordPress site: you open your site and it redirects you (or your visitors) to gambling, pharmacies, scams, or adult content . The owner often doesn't see anything suspicious in the admin — but visitors and Google see the infected site.
What does it look like (are you affected?)
- The page redirects to an unknown site — often only on mobile or only for Google visitors
- In Google results , foreign spam ("Japanese SEO spam", "pharma hack") is displayed under your page, which you cannot see in the admin
- Google Search Console reports "Deceptive content", "Cloaking" or "Malware"
- The browser displays a red "Deceptive site ahead" warning to visitors
Behind this are massive campaigns that have infected tens of thousands of WordPress sites (known under the names DollyWay and VexTrio , each 20,000+ sites). The entry point is almost always an outdated vulnerable plugin or theme .
What to do now
- Change all passwords (WordPress, hosting, FTP, database) and check for unknown administrators .
- Look for embedded code — suspicious
.phpfiles inwp-content/uploadsand foreign JavaScript/iframes in the theme or inwp_options. - Restore a clean copy from before the infection, then update the core, theme and all plugins .
- After cleaning, request a re-review in Google Search Console.
Important: if you restore the backup and don't close the vulnerability they entered, the redirect will return in a couple of days.
Is your page redirecting or has Google marked it as hacked? Send us the link — diagnosis is free, and we'll get back to you within 5 minutes. Urgent repair →
WMD — Super fast support.