I have a cloud-based server running with CentOS 6.0 and CSF installed. Today I got a message from my host that one of my WordPress installations is hacked and used for phishing.
But I don't know how this has happened. I do not know where it is happening. What the best practice here? How can I check what has happened and stop it?
EDIT: My host said now that he wasn't sure it was wordpress, but was suspecting it. Do I really need to delete everything and reinstall. This is over 10 sites, and it will be a lot of work.