My WordPress site was hacked. What do I do first?
Change your hosting and WordPress passwords now, take the site offline or into maintenance mode if it is serving spam, and do not delete anything yet: the evidence matters. Almost every hacked site can be cleaned or rebuilt, and sometimes the rebuild is cheaper.
The longer answer
In practice.
The first hour
Rotate credentials (hosting, WordPress admin, database, FTP), check whether
your email domain is blacklisted, and screenshot anything strange. If customer
data may be involved, note when you noticed: Australian privacy law cares about
timelines, and so should you.
The clean-up, properly
Isolate the site, rebuild from known-good plugin and theme copies plus a clean
database export, rotate every secret, and close the way in, which is usually an
outdated plugin or a reused password. A scan-and-hope cleanup that leaves the
door open is how sites get hacked twice.
Clean or rebuild?
An old site with a pile of abandoned plugins is often cheaper to rebuild lean
than to disinfect. You get that comparison honestly before spending, per
WordPress, and either way you end up holding all your
own keys, which is how this gets prevented.
Same rabbit hole