Unknown Admin User in WordPress: What to Do (In the Right Order)

Higher-risk issue — be cautious and consider professional help sooner.

You found an unknown admin user in WordPress — an administrator account you did not create — and need to know whether it is a hacker, a forgotten developer, or a plugin, and what to do without making things worse.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

Sometimes an unknown admin is harmless: a developer who set up the site years ago, a host's support login, or a staff member someone else added. That is why you ask around first. But an unexplained Administrator, especially with a strange email address, is one of the clearest signs a WordPress site has been compromised. Attackers add their own admin so they can get back in whenever they like, install plugins, and plant spam or malware. It is often a symptom rather than the whole problem — see WordPress site hacked for the bigger picture.

The order of operations matters because the admin account is rarely the only way in. Whatever vulnerability let the attacker create it — an outdated plugin, a reused password, a leaked login — may still be open, and many attacks also drop hidden files (backdoors) that can recreate the account within minutes of you deleting it. Some malware goes further and hides the user from the Users list altogether, which is why a mismatched count is so telling. Deleting the visible account first can tip off an automated attacker, destroys your clues, and gives false confidence that the site is clean.

A sensible sequence is: record the details, back up, lock down every password and application password, update or remove vulnerable plugins and themes, scan the files and database for backdoors, and only then remove the rogue account. When you delete it, WordPress asks what to do with its content — choose to attribute it to your own account so you can review anything it published. Afterwards, keep watching Users for a few weeks. If the account comes back, the backdoor is still there and the site needs a proper cleanup.

What not to do

When to get help

Get help if you cannot explain the account after asking everyone who has had access, if the admin count does not match the list, if the account reappears after deletion, or if your site handles customer data or payments. Those are signs of an active compromise, and a partial cleanup can leave a backdoor that keeps the attacker in for months while your site quietly sends spam or redirects visitors. An experienced cleaner checks the database and files directly for hidden users and injected code, closes the hole that let them in, and confirms nothing comes back.

Glenn, who runs WebsiteSelfHelp, investigates and cleans up hacked WordPress sites for small businesses, including hidden admin accounts and the backdoors that come with them. Request a direct review, describe the account you found and anything else odd, and you will get a straight answer on how serious it is and what the cleanup involves — no passwords needed to start.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

Why is there an unknown admin user in my WordPress site?

Either someone with legitimate access created it (a developer, host, or staff member) or an attacker added it after getting in through a vulnerable plugin, weak password, or stolen login. If nobody who worked on the site recognizes it, treat it as a break-in.

Should I delete an unknown WordPress admin account right away?

Not as your first step. Record its details, back up the site, and change all passwords first. Then scan for backdoors and remove the account. Deleting it first often just leads to it being recreated.

How can a WordPress admin user be hidden?

Malicious code can filter the Users screen so a particular account never shows, even though it still exists in the database. A mismatch between the Administrator count and the admins you can see is the telltale sign.

Does a new admin user mean my WordPress site was hacked?

Not always, but if nobody with legitimate access created it, assume yes. Attackers create admin accounts so they can get back in, and there are usually other changes you cannot see yet.

Will changing my password remove the hacker?

Only partly. A new password locks out anyone using the old one, but it does nothing about a rogue admin account, application passwords, or backdoor files. All of those need dealing with separately.

How did someone create an admin account on my site?

The most common routes are an outdated plugin or theme with a known security flaw, an admin password that was reused and leaked elsewhere, or malware on a computer that logged in to the site.

How much does it cost to clean up a WordPress site with a rogue admin?

It depends on how deep the compromise goes. A quick case with no backdoors is modest work; a site with hidden files and database injections takes longer. Expect anywhere from a small fixed fee to a few hundred dollars from a reputable cleaner, and ask for a quote before work starts.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible