I’m just starting to learn WordPress, so I’m no expert, but have you seen this site: “Top 5 WordPress Security Tips You Most Likely Don’t Follow”:
https://www.wptavern.com/top-5-wordpress-security-tips-you-most-likely-dont-follow
The easiest and most effective measure to implement is the ‘.htaccess’ tip. Warning: read my post at the bottom of that page. Make sure you have FTP access to your site regardless of .htaccess, and can delete the .htaccess file if it’s incorrect and locks even you out.
Let me know if this fixes your problem, I’m concerned about my own vulnerability.