Skip to content
WP Hack FixEst. 2005

Locked out of WordPress admin, or seeing users I didn't create

Losing access to your own dashboard, or finding an administrator you've never heard of, is a strong sign someone else has control of the site. Speed matters here: while they hold an account, they can keep changing things faster than you can undo them.

We reply within 1 business day (Mon–Fri, 9–5 ET)

What you're seeing

  • Your password no longer works, and the reset email never arrives
  • Your account has been demoted, or deleted entirely
  • Administrator accounts with odd names or unfamiliar email addresses
  • The admin email address on the site has been changed
  • New plugins or themes you didn't install

Why it happens

An attacker took over your account

Once in, they change the password and the recovery email so you can't take it back.

They added their own administrator

A quiet way to keep access even after you change your own password.

A vulnerable plugin created the account

Some plugin vulnerabilities let an attacker create an administrator without ever knowing a password.

Password reuse or a compromised computer

If the same password is used elsewhere, or your machine is infected, attackers get in without touching the site's code.

Reset emails going nowhere

If they changed the site's email settings, password resets go to them instead of you.

What to do right now

Do this

  • Change your hosting password first, from a device you trust. Hosting access outranks WordPress access
  • If you still have hosting access, list the WordPress users through the control panel's database tool
  • Check for admin accounts and email addresses you don't recognize, and write them down before changing anything
  • Check your email account security too, since that's how account recovery works

Don't do this

  • Don't delete unknown accounts and stop there. The way in is usually a file, and the accounts come back
  • Don't reinstall WordPress over the top to force a reset. It doesn't remove backdoors
  • Don't reuse your old password anywhere else once it's been exposed

How we fix it

  1. 1Get you back in through hosting-level access, without relying on the compromised account
  2. 2Audit every user account and remove the ones that shouldn't exist
  3. 3Reset security keys so every session, including theirs, is logged out
  4. 4Find and remove the backdoor or vulnerable plugin that created the access
  5. 5Restore your admin email settings, then update and harden the site

Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing

Questions

Can you get me back in without my password?

Yes, as long as you have hosting or database access, which we can reset access through. That's why hosting credentials matter more than the WordPress password in a situation like this.

I deleted the strange admin user. Am I safe now?

Not necessarily. If the attacker uploaded a backdoor file, they can recreate the account whenever they want. The files need checking too.

Could this be my own plugin acting up?

Occasionally a role or membership plugin causes a lockout with no hack involved. We check for that before assuming the worst, and we'll tell you if that's all it was.

Other symptoms

Hacked right now? Let's get it fixed.

Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)