Skip to content

Restore WordPress core files

  1. Choose the intended servers and sites. Start with one installation.
  2. Preserve a usable backup and check any intentional core customizations.
  3. Open Choose action → Bulk tools, search for Restore WordPress core files, then choose that entry.

Bulk tools search showing Restore WordPress core files in the Core group

Review the intended site before confirming core replacement. This action entry is not evidence of a completed repair. Select the image to view it full size; use your browser’s Back command to return.
  1. In Confirm WordPress action, check Selected sites, Action and options and Target servers. Continue only when the replacement is intended, or use Cancel.

Native core-restoration confirmation showing selected sites, target servers and the data-change warning

Review the core replacement and warning before confirming. This screen has not submitted a restoration; the site identity is concealed. Select the image for full size; use browser Back to return.
  1. Read every site’s final result, including skips. Finished can include failed sites; see Read the outcome.

This replaces modified core with clean copies; it does not restore the database or clean themes/plugins/accounts. Check public pages and sign-in afterwards.

Experienced administrators can use a root terminal on the server hosting the sites:

Terminal window
cpfence --bulk-force-wp-core-files

Review /var/log/cpfenceav/wp-sites-list.txt and the inventory and replacement confirmations first. This uses the server’s listed installations, not checked WebUI rows. Keep a usable backup and preserve intentional core changes before overwriting files.

Read each site’s final output and check its WordPress version, public pages and sign-in. This downloads fresh core files while skipping wp-content; it does not restore the database or clean plugins, themes, accounts or unrelated malicious files. For an infected site, continue the cleanup procedure rather than treating this step as complete recovery.