>_
Delvok
← Back to Blog
Security Guide

wp-vcd.php Malware Removal: How to Eradicate the Self-Healing WordPress Backdoor

September 30, 2026·Delvok Security Team·3 min read

If your security scanner flags a file named wp-vcd.php or class.wp.php inside your /wp-includes/ directory, your server has encountered one of the most resilient self-healing infections in the WordPress ecosystem: the wp-vcd malware campaign.

This malware almost exclusively originates from "nulled" (pirated) premium themes and plugins downloaded from third-party distribution forums. Once executed, it does not stay inside the plugin you downloaded - it spreads laterally into every active and inactive theme on your hosting account.

Why Deleting the File Does Not Work

Most website owners locate wp-vcd.php and hit delete. Within 12 hours, the file is back.

Here is why: wp-vcd uses a distributed parent-child architecture. When the malware runs, it injects a small base64 loader into the functions.php file of every single theme installed on your server.

If you delete wp-includes/wp-vcd.php, the very next time a visitor loads any page on your website, WordPress executes functions.php. The injected hook notices that wp-vcd.php is missing, pulls the source code from its encoded payload, and recreates the file.

How to Tell If You Are Infected

  1. Rogue Admin Accounts: Users named 100010010, admin_backup, or random numeric handles appearing in wp_users.
  2. Hidden Blackhat SEO Links: Injected footer links advertising pharmaceuticals or gambling that only render for non-administrative visitors.
  3. Google Search Console Penalties: Cloaked doorway pages detected across your domain index.

To permanently eradicate wp-vcd, you cannot clean individual files manually. You must simultaneously clean every theme's functions.php, replace the core wp-includes directory, and sanitize your database options.

If your site is currently infected and re-infecting itself daily, submit a Delvok rescue ticket and our engineers will disinfect the entire installation in under 4 hours.

What Delvok Does Differently

Every site we rescue is migrated to isolated container infrastructure — your own web root, database, and server process. 24/7 monitoring catches threats before they become problems. Forensic-grade remediation ensures nothing is left behind.

Get Protected