Locked out of WordPress admin, or seeing users I didn't create
Losing access to your own dashboard, or finding an administrator you've never heard of, is a strong sign someone else has control of the site. Speed matters here: while they hold an account, they can keep changing things faster than you can undo them.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- Your password no longer works, and the reset email never arrives
- Your account has been demoted, or deleted entirely
- Administrator accounts with odd names or unfamiliar email addresses
- The admin email address on the site has been changed
- New plugins or themes you didn't install
Why it happens
An attacker took over your account
Once in, they change the password and the recovery email so you can't take it back.
They added their own administrator
A quiet way to keep access even after you change your own password.
A vulnerable plugin created the account
Some plugin vulnerabilities let an attacker create an administrator without ever knowing a password.
Password reuse or a compromised computer
If the same password is used elsewhere, or your machine is infected, attackers get in without touching the site's code.
Reset emails going nowhere
If they changed the site's email settings, password resets go to them instead of you.
What to do right now
Do this
- Change your hosting password first, from a device you trust. Hosting access outranks WordPress access
- If you still have hosting access, list the WordPress users through the control panel's database tool
- Check for admin accounts and email addresses you don't recognize, and write them down before changing anything
- Check your email account security too, since that's how account recovery works
Don't do this
- Don't delete unknown accounts and stop there. The way in is usually a file, and the accounts come back
- Don't reinstall WordPress over the top to force a reset. It doesn't remove backdoors
- Don't reuse your old password anywhere else once it's been exposed
How we fix it
- 1Get you back in through hosting-level access, without relying on the compromised account
- 2Audit every user account and remove the ones that shouldn't exist
- 3Reset security keys so every session, including theirs, is logged out
- 4Find and remove the backdoor or vulnerable plugin that created the access
- 5Restore your admin email settings, then update and harden the site
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
Can you get me back in without my password?
Yes, as long as you have hosting or database access, which we can reset access through. That's why hosting credentials matter more than the WordPress password in a situation like this.
I deleted the strange admin user. Am I safe now?
Not necessarily. If the attacker uploaded a backdoor file, they can recreate the account whenever they want. The files need checking too.
Could this be my own plugin acting up?
Occasionally a role or membership plugin causes a lockout with no hack involved. We check for that before assuming the worst, and we'll tell you if that's all it was.
Other symptoms
- Visitors get redirectedYour site sends people to spam, scam, or adult sites, often only on mobile or from Google.
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Strange pages in GoogleJapanese, pharma, or casino pages you never created show up under your domain.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- It keeps coming backYou cleaned the site, and the malware was back within days.
- Card skimmer on checkoutCustomers' card details are being captured at checkout by injected code.
- Fake login pagesSomeone is hosting fake bank or Microsoft login pages in a hidden folder on your site.
- Pharmacy spam in GoogleYour search listings mention pills or pharmacies, even though your pages look normal.
- A scanner says I'm infectedWordfence, Sucuri, or another plugin reports malware you can't get rid of.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)