Run a full scan with Wordfence, also check under Users section in case they added themselves.
Hi @jronna,
Russell is correct, it’s certainly worth running a full scan to ensure files or malicious code haven’t been inserted into your site and check for any users (especially with administrative access) that you did not add or recognize.
Secondly, we do provide 2FA and reCAPTCHA through our Wordfence > Login Security module. One or both of these, with 2FA set to “Required” for administrators greatly reduces the possibility of a malicious source gaining access even if your password becomes known. Make sure to set a grace period if there are other administrators on your site that need time to comply with the changes: https://www.wordfence.com/help/login-security/#two-factor-authentication-options
As a rule, any time I think someone’s site has been compromised I also tell them to update their passwords for their hosting control panel, FTP, WordPress admin users, and database. Make sure to do this.
Thanks,
Peter.