Initial assessment without passwords Quote before intervention One accountable specialist from start to finish

Hosting Dns Containment

Malware Affects Every WordPress Site in the Same cPanel Account

Scope and clean WordPress malware across an entire cPanel account, including shared users, permissions, cron, email and forgotten sites.

When unrelated WordPress sites under one cPanel account show the same redirect, PHP file or spam page, the shared hosting user is the likely security boundary. Cleaning each dashboard separately misses panel sessions, common FTP users, cron and writable paths.

Contain the whole account and preserve evidence before restoring individual sites.

Confirm the shared pattern

Record affected domains, document roots, first/last detection time, file paths and hashes. Compare payload strings and external destinations.

Matching indicators suggest common access, but do not prove which site was first. A vulnerable addon domain and stolen panel password can coexist.

Include staging, parked domains and subdirectories in the inventory.

Coordinate containment with the host

Ask the provider to preserve cPanel login, file-manager, FTP/SFTP, cron and malware-scanner logs. Revoke unknown sessions and restrict public PHP execution where malicious pages are active.

Use the provider’s verified support route. Do not follow reset links from suspicious suspension emails.

Agree how clean static notices and recovery access will work.

Map account-level trust

Inventory cPanel users, FTP accounts, databases/users, email accounts/forwarders, cron, SSH keys, DNS zones and addon-domain document roots.

Record filesystem owners and whether one site can write into another. Shared public_html nesting often expands the effect of one compromised application.

Do not change permissions to arbitrary restrictive values before understanding the host’s PHP handler.

Preserve files and databases

Take an account snapshot with timestamps and export each database. Store evidence outside all public roots and restrict it because it contains personal data, secrets and malware.

Save provider detections and hashes. Use a duplicate for analysis.

Do not rely on backups created after compromise as clean restore points.

Clean every reachable installation

Replace core/plugins/themes from verified sources, manually review custom code and remove database payloads, hidden users and malicious schedules.

Retire forgotten installations and old ZIP/backups exposed under public directories. Patch or remove the original vulnerable component wherever installed.

One unclean subdirectory can reinfect all repaired sites through shared ownership.

Recover account access

Secure owner email and devices, enable panel multi-factor authentication, revoke sessions and rotate cPanel, FTP/SFTP, database and WordPress credentials.

Remove shared and former-contractor accounts. Update deployment/backup automation before revoking old secrets.

Review unknown mailboxes and forwarders that could receive password resets or send spam.

Review domain and account recovery controls

Addon domains may use DNS managed inside cPanel while the registrar remains elsewhere. Export every zone, verify nameservers, A/AAAA/CNAME/MX records and remove only confirmed malicious changes.

Check the primary account contact, notification addresses and support PIN/security questions. An attacker who controls the recovery mailbox can reset the panel after password rotation. Secure that mailbox independently, review forwarding/app passwords and ask the provider to flag the account for stronger identity verification during recovery.

Record which person owns renewals and domain transfers. Enable domain lock and DNS change alerts where supported.

Improve isolation

Where the host permits, give each important site a separate subscription/user, database credential and deployment account. Keep staging authenticated and backups outside web roots.

If cPanel cannot isolate sites under the plan, consider moving critical stores or lead sites to separate accounts after cleanup.

Isolation limits future blast radius; it does not replace patching and access controls.

Verify account-wide stability

Restore one site at a time. Test public output, forms, email and authorised checkout, then monitor hashes and panel logins beyond the previous recurrence interval.

Run normal cron, backups and deployments to ensure they do not restore infected artefacts.

When urgent account cleanup is needed

Request professional help when several sites change together or ownership overlaps. Send the domain list and shared indicators, not cPanel credentials.

A complete repair restores the account boundary, cleans every application and proves cross-site writes no longer recur.

BEFORE YOU SEND THE REQUEST

Frequently asked questions.

Do you ask for passwords in the form?+

No. The public form never requests access. Secure credentials are requested only after the scope and quote are approved.

Who reviews the incident?+

The request goes to Jordi Ensenyat, founder of Code Barcelona and a WordPress specialist with more than 15 years of experience.

Is anything changed before the quote?+

No. Visible symptoms and scope are reviewed first. Intervention begins after approval and with a rollback path prepared.

Do you work internationally?+

Yes. WP Repair handles WordPress and WooCommerce incidents in English and Spanish through a remote service.

Assess my incident