If you think your website was hacked, start by changing passwords for hosting, FTP or SFTP, CMS admin, database, email, and domain registrar accounts from a clean device.
Take a copy of the current files before deleting anything. The infected state can help identify how the attacker got in and what files were changed.
Check for new admin users, unknown cron jobs, modified .htaccess rules, suspicious PHP files, and recently changed uploads. Attackers often leave more than one way back in.
Restore from a known clean backup only after closing the entry point. If the vulnerable plugin, weak password, or exposed file remains, the site can be compromised again.
After cleanup, update software, rotate keys, review logs, and watch search engine results for spam pages that may need removal requests.