Why This Is a Hack, Not a Bug
A malicious redirect doesn't happen from a misconfiguration — it means an attacker has already placed code somewhere in the site that intentionally sends visitors to a different destination, usually a spam page, ad-fraud site, or scam page monetizing the traffic. It's worth treating this the same way as any other compromise: find the injected code, remove it, and close whatever let the attacker in — not just delete the visible symptom.
Step 1: Check for Device- or Referrer-Specific Behavior First
Many injected redirect scripts are deliberately conditional — they only trigger for mobile visitors, or only for visitors arriving from a Google search result, specifically so the site owner checking the site directly in a desktop browser sees nothing wrong. Before concluding you don't have this problem, test from an incognito mobile browser, or use a free site-checker tool that simulates a search-engine referrer.
Step 2: Check .htaccess for Injected Rewrite Rules
Via FTP or your host's file manager, open .htaccess in the site's root and look for any RewriteRule or RewriteCond lines you don't recognize, especially ones referencing an unfamiliar external domain. These are a common and relatively easy place for attackers to inject a redirect, since .htaccess executes before WordPress even loads.
Step 3: Check Theme and Plugin Files
Review your active theme's functions.php file for unfamiliar code, particularly anything referencing header('Location: or wp_redirect( that you didn't add. Also check for plugin files with names that look legitimate but aren't part of any plugin you actually installed — a common technique is dropping a file like wp-cache.php or similarly named file directly into /wp-content/ to blend in. A security scanner like Sucuri or Wordfence will often flag these automatically by comparing files against known-clean versions.
Step 4: Check the Database
Via phpMyAdmin, check the wp_options table for the siteurl and home rows — if either has been altered to point somewhere unexpected, that's a direct cause of site-wide redirects. Also check widget and theme option rows for injected <script> tags, which is another common place to hide redirect logic where it won't be noticed in a normal file review.
Step 5: Close the Entry Point
Removing the redirect code fixes the symptom but not the cause. Update every plugin, theme, and WordPress core to their latest versions, remove anything you're not actively using, and change every password associated with the site. If the entry point isn't identified and closed, the same vulnerability typically lets the redirect script get reinjected within days.