self-moderation mode enabled.
I really admire your restraint ??
H3ODST you’ve a lot of work ahead of you. Backup your files and database now. If you make a mistake you’ll need to put it all back to the way it was, even if it’s a hacked version.
Now where did I put that boiler plate…
Read this
https://ocaoimh.ie/2008/06/08/did-your-wordpress-site-get-hacked/
And then read it again.
Read this too
https://codex.www.ads-software.com/Hardening_WordPress
Upgrade to the latest version if you have not already. You need to see if there are any users added to WordPress that you don’t know about/don’t belong there.
You need to go through your files and find where the spammy links are being added. If it’s in wp-config.php or some other file, you’ll need to make sure that is cleaned up before you can consider yourself good file wise. Look everywhere and use fresh copies of your WordPress installation, plugins, and themes.
Look at your posts and comments and see if there are any spammy links there. You can export your whole blog to WXR and then examine the whole thing in your favorite text editor.
Look at your server’s log files. If you are on a shared server, get help from your provider. You need to identify if this was a compromise of WordPress or your server. If you do not identify the entrance which the attacker got in, odds are they will be back.
Once you have cleaned up your hacked blog, harden it so this does not happen again.
Good luck.