WordPress Incident Response & Rebuild
Worldwide
WordPress Incident Response — Compromised Site Cleanup & Secure Rebuild I run a WordPress site on a self-managed Ubuntu VPS (Apache, PHP 8.x, MySQL) that has been compromised. I need an experienced security specialist to contain it, rebuild it clean, and make sure it stays clean. Current situation: Site front-end returns a blank page (malware fatals during page load); wp-admin remains accessible Confirmed webshell/loader files planted in core directories, fake plugin and theme folders acting as droppers, and a malicious must-use plugin Malware files are owned by the web server user and regenerate automatically after deletion, indicating database-resident persistence Restoring a 3-month-old snapshot did not resolve it — the infection returned, suggesting the compromise predates the snapshot Server previously had root SSH access via password authentication; unrecognized administrator accounts exist in the WordPress user table Likely initial vector: a known-vulnerable file manager plugin (unauthenticated RCE) Scope of work: Containment and triage of the current environment Forensic identification of the persistence mechanism and initial entry vector Clean rebuild on fresh infrastructure — new instance, current WordPress core, plugins/themes reinstalled from official sources only Selective content migration (posts, pages, media, verified user accounts) without carrying the infected database wholesale; audit and clean the user table, options table, and scheduled tasks Credential rotation across server, database, WordPress admins, salts, and integrations Hardening: key-only SSH, least-privilege file permissions, WAF, monitoring, update policy Written summary of findings — what was found, how they got in, what was changed Post-rebuild monitoring window to confirm no reinfection Requirements: Demonstrable WordPress incident response experience (not general WP development) Comfortable working directly on a Linux VPS via SSH; strong Apache/PHP/MySQL troubleshooting Experience with WordPress database-level malware and persistence mechanisms WP-CLI proficiency Available to start immediately; site is currently offline To apply, please answer: What's your approach to migrating content off an infected database safely? What's your estimated timeline and your rate structure for this scope? The site holds registered user accounts and user-generated records, so discretion and careful data handling matter. Happy to discuss specifics privately with shortlisted candidates.
$250.00
Fixed-price- IntermediateExperience Level
- Remote Job
- One-time projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:2 days ago
- Hires:1
- Interviewing:9
- Invites sent:14
- Unanswered invites:0
About the client
- EstoniaTallinn7:55 AM
- $85K total spent106 hires, 2 active
- 3,577 hours
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by