Unknown Admin User in WordPress: What to Do (In the Right Order)
Higher-risk issue — be cautious and consider professional help sooner.
You found an unknown admin user in WordPress — an administrator account you did not create — and need to know whether it is a hacker, a forgotten developer, or a plugin, and what to do without making things worse.
Common signs of this issue
- Users in your WordPress dashboard shows an unknown admin user — an Administrator you did not create and do not recognize.
- The username looks random, generic (like "wpadmin", "support", or "adm1n"), or imitates a real one with a small change.
- The account's email address is at a free email provider or a domain you have never heard of.
- The Administrator count at the top of the Users screen is higher than the number of admins actually listed.
- You got a "New user registration" or password-change email from your site that you did not trigger.
- It appeared alongside other odd behavior: unfamiliar plugins, spam pages in Google, or redirects to strange sites.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Don't delete it yet. First open Users, click the unknown account, and record the username, email address, and display name. Take a screenshot. You will want these details later if this turns out to be a break-in.
- Rule out the innocent explanations. Ask anyone who has worked on the site — a past developer, an agency, your host's support team, or a marketing contractor. Some managed hosts and support services add their own admin account, and some plugins create special roles.
- Compare the counts. On the Users screen, look at the number next to Administrator in the filter links and count the admins actually listed. If the number is higher than what you can see, something is hiding an account from the list — a strong sign of malicious code.
- Check Settings, then General: Membership should normally be unticked unless you need public sign-ups, and New User Default Role should be Subscriber (or Customer on a shop). If the default role is Administrator, that is almost never an accident.
- Make a full backup of files and database now, even though the site may be compromised. It preserves the evidence of what happened and gives you a fallback if the cleanup goes wrong. Label it clearly so nobody restores it by mistake later.
- Look at Plugins for anything you do not recognize, and note plugins that have not been updated in a long time. Out-of-date plugins with known flaws are the usual way attackers create admin accounts.
- Open your own admin profile and each legitimate admin's profile, and scroll to Application Passwords. Any entry you did not create is a second way in that survives a normal password change.
- If you have a security plugin such as Wordfence or Sucuri, check its activity or login log for when the account was created and which IP address used it. If you have hosting access, your host can also tell you when files last changed.
- Only then, in this order: change every admin password (and your hosting, FTP/SFTP, and database passwords), have the site scanned for backdoors, and then remove the unknown account.
What this usually means
Sometimes an unknown admin is harmless: a developer who set up the site years ago, a host's support login, or a staff member someone else added. That is why you ask around first. But an unexplained Administrator, especially with a strange email address, is one of the clearest signs a WordPress site has been compromised. Attackers add their own admin so they can get back in whenever they like, install plugins, and plant spam or malware. It is often a symptom rather than the whole problem — see WordPress site hacked for the bigger picture.
The order of operations matters because the admin account is rarely the only way in. Whatever vulnerability let the attacker create it — an outdated plugin, a reused password, a leaked login — may still be open, and many attacks also drop hidden files (backdoors) that can recreate the account within minutes of you deleting it. Some malware goes further and hides the user from the Users list altogether, which is why a mismatched count is so telling. Deleting the visible account first can tip off an automated attacker, destroys your clues, and gives false confidence that the site is clean.
A sensible sequence is: record the details, back up, lock down every password and application password, update or remove vulnerable plugins and themes, scan the files and database for backdoors, and only then remove the rogue account. When you delete it, WordPress asks what to do with its content — choose to attribute it to your own account so you can review anything it published. Afterwards, keep watching Users for a few weeks. If the account comes back, the backdoor is still there and the site needs a proper cleanup.
What not to do
- Don't delete the unknown admin as your very first move. Record its details and secure your passwords first, or you may lose the evidence and it may simply be recreated.
- Don't assume the problem is solved once the account is gone. The way the attacker got in is usually still open.
- Don't restore an old backup without checking it. If the break-in happened weeks ago, the backup may contain the same backdoor.
- Don't reuse the old passwords anywhere, and don't change only your WordPress password. Hosting, FTP, database, and email logins all need changing too.
- Don't log in to the site from a computer you suspect is infected. Stolen passwords from a compromised PC are a common source of these accounts.
- Don't install several security plugins at once in a panic. They can conflict, lock you out, and slow the site without cleaning anything.
When to get help
Get help if you cannot explain the account after asking everyone who has had access, if the admin count does not match the list, if the account reappears after deletion, or if your site handles customer data or payments. Those are signs of an active compromise, and a partial cleanup can leave a backdoor that keeps the attacker in for months while your site quietly sends spam or redirects visitors. An experienced cleaner checks the database and files directly for hidden users and injected code, closes the hole that let them in, and confirms nothing comes back.
Glenn, who runs WebsiteSelfHelp, investigates and cleans up hacked WordPress sites for small businesses, including hidden admin accounts and the backdoors that come with them. Request a direct review, describe the account you found and anything else odd, and you will get a straight answer on how serious it is and what the cleanup involves — no passwords needed to start.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
Why is there an unknown admin user in my WordPress site?
Either someone with legitimate access created it (a developer, host, or staff member) or an attacker added it after getting in through a vulnerable plugin, weak password, or stolen login. If nobody who worked on the site recognizes it, treat it as a break-in.
Should I delete an unknown WordPress admin account right away?
Not as your first step. Record its details, back up the site, and change all passwords first. Then scan for backdoors and remove the account. Deleting it first often just leads to it being recreated.
How can a WordPress admin user be hidden?
Malicious code can filter the Users screen so a particular account never shows, even though it still exists in the database. A mismatch between the Administrator count and the admins you can see is the telltale sign.
Does a new admin user mean my WordPress site was hacked?
Not always, but if nobody with legitimate access created it, assume yes. Attackers create admin accounts so they can get back in, and there are usually other changes you cannot see yet.
Will changing my password remove the hacker?
Only partly. A new password locks out anyone using the old one, but it does nothing about a rogue admin account, application passwords, or backdoor files. All of those need dealing with separately.
How did someone create an admin account on my site?
The most common routes are an outdated plugin or theme with a known security flaw, an admin password that was reused and leaked elsewhere, or malware on a computer that logged in to the site.
How much does it cost to clean up a WordPress site with a rogue admin?
It depends on how deep the compromise goes. A quick case with no backdoors is modest work; a site with hidden files and database injections takes longer. Expect anywhere from a small fixed fee to a few hundred dollars from a reputable cleaner, and ask for a quote before work starts.