1. Take a copy before you touch anything
Download your files and database as they are, even though they are infected. You need a record in case you have to compare, and a way back if a fix goes wrong.
2. Contain it
Put the site into maintenance mode, or ask your host to suspend it, so visitors are not sent to bad pages. Change your hosting, WordPress admin, database and email passwords from a clean computer.
3. Restore from a clean backup
If you have a backup from before the problem, restoring it is usually the fastest route. Check the backup really is clean, because some infections sit for weeks before they show.
4. Update everything, remove what you do not use
Update WordPress, your theme and every plugin. Delete plugins and themes you are not using, and any you cannot update. Most attacks come in through out of date plugins.
5. Check for leftovers
Look for admin users you did not create, strange files in your uploads folder, and changes to your home page. Run a malware scan with a well known security plugin or ask your host to scan.
6. Tell Google and your host
Check Google Search Console for a security warning and request a review once you are clean. Your host may be able to help with logs that show how the attacker got in.
7. Decide whether to stay
If this is the second time, or you cannot keep up with updates, the real fix is a site with nothing to attack. A static site has no plugins, no login page and no database, which is why we rebuild WordPress sites this way.
Questions
How do I know if my site has been hacked?
Common signs are redirects to other sites, strange pages in Google results, a browser or Google warning, new admin users, or your host suspending the account.
Should I pay someone to clean it?
If the site is important and you are not comfortable doing it yourself, yes. A rushed clean up that misses a backdoor means being hacked again.