I keep getting notifications from my hosting provider that memory or CPU limits are being reached, which is unlikely as I haven’t launched my site.
Looking at the Google console I see that it has 102,497 indexed pages and 268,667 not indexed pages. My site has about 20 max incl. posts!!! Googling site:mydomain.com also shows 1,440 results.
All of them are gibberish urls, and return 404 page as expected so this feels like a hack. But my issue is that this is likely the reason my server is being jammed daily.
I have a robots.txt already, which I read in a different thread to be of use. But how do I clean this up and stop from happening again?? WP is running the latest version, as are all the plugins.
[ad_2]
Your site was almost certainly compromised. In the Wiki there are a list of resources:
[https://www.reddit.com/r/Wordpress/wiki/index/#wiki_been_hacked.3F_don.27t_panic.21](https://www.reddit.com/r/Wordpress/wiki/index/#wiki_been_hacked.3F_don.27t_panic.21)
“Latest version” software can still contain vulnerabilities, especially if it hasn’t been updated (by the developer) for a while.
Install Wordfence and run a scan.
That said, seeing unknown URLs in GSC doesn’t necessarily mean your site is compromised.
there is a malicious script somewhere. I see them usually in the header or footer php files but it might be outside of your wordpress files, might not be.
plugin versions don’t matter if your password is admin123.
Get Wordfence and run a high sensitivity scan, change the settings to include files outside wordpress in the scan.