Contain the compromise before optimizing anything else
The first task is to preserve evidence and stop continued changes. Credentials, administrator accounts, plugins, themes, uploads, scheduled tasks and hosting access may all need review depending on the compromise.
A visual cleanup is not enough if the attacker’s persistence mechanism remains active.