Contain, clean, harden and monitor — with a documented incident report.
Containment, clean restore from a known-good state, credential rotation, hardening across users + secrets + WAF, and a written incident report.
Typical results within 30–60 days of shipping.
The stubborn WordPress bugs your last dev couldn’t reproduce.