WordPress: "Sorry, You Are Not Allowed to Access This Page"
You log in to WordPress and get "Sorry, you are not allowed to access this page" instead of your dashboard or a settings screen. WordPress is saying your account lacks permission, and the reason is usually fixable.
Common signs of this issue
- You log in successfully, but the dashboard shows "Sorry, you are not allowed to access this page." instead of loading.
- The main dashboard works, but one settings page or plugin screen gives the error.
- It started right after you deactivated, deleted, or updated a plugin.
- It appeared after the site was moved to a new host or domain, or restored from a backup.
- Your account now shows as a lower role such as Subscriber, or you can no longer see menus like Plugins, Users, or Settings.
- You notice admin accounts you do not recognize, or your own admin account has disappeared.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Look at the web address in your browser. If it contains something like admin.php?page= followed by a plugin's name, you are trying to open a screen that belonged to a plugin that is now deactivated or removed. Go to the plain dashboard address (your domain followed by /wp-admin/) instead. If that loads normally, nothing is wrong beyond an old link or bookmark.
- Clear your browser's cookies for the site, or open a private window, and log in again. Stale login cookies after a migration or a password change can cause odd permission errors.
- If you can reach the dashboard, open Users and check your own role. It should say Administrator. If the Users menu is missing entirely, your account has lost its administrator role.
- Think about what changed just before the error. A plugin deactivation, a security plugin setting, a site move, or a restore from backup each points to a different cause, and that timeline is the most useful thing you can give anyone helping you.
- If the site was recently migrated, ask whoever moved it whether the database table prefix changed. WordPress stores user roles in database entries named with that prefix. If the prefix in the site's configuration file no longer matches the names inside the database, every user loses their permissions and you see this error — even though your password still works.
- If you use a security or user-role plugin, check whether it restricts admin pages by user, IP address, or role. Some security tools can lock administrators out of specific screens after a settings change.
- Check for signs of a hack: unfamiliar admin users, a changed email address on your account, or password reset emails you did not request. Attackers sometimes demote or delete the owner's admin account after creating their own.
- Ask your host whether they can see your user role in the database, or whether they have a tool to create a new administrator account. Many managed WordPress hosts can do this from their control panel.
What this usually means
WordPress shows this message when it knows who you are but does not think your account has permission for the page you asked for. In the simplest case the page no longer exists: you deactivated a plugin, and your bookmark or browser history still points to that plugin's settings screen. WordPress cannot tell a missing page from a forbidden one, so it shows the same message. That version is harmless.
The more serious version is when the whole dashboard refuses you. That usually means your administrator role has gone missing from the database. After a migration, the most common reason is a table prefix mismatch: the configuration file says one prefix, but the stored user roles and permissions were saved under the old one, so WordPress cannot find anyone's permissions. A badly completed restore, a plugin that edits user roles, or a manual database change can have the same effect.
Sometimes the cause is security-related. A hacker who gets in may demote or remove your admin account so you cannot undo their changes, and some security plugins lock administrators out if they are set too tightly. In those cases, getting back in is only step one — you also need to find out how the change happened. If there is any sign of an intruder, treat it as a hacked site, not just a login problem.
What not to do
- Don't reinstall WordPress or delete and re-add your user account. You can lose content, settings, and the evidence of what went wrong.
- Don't edit the database or the table prefix setting yourself unless you have a fresh backup and know exactly what you are changing.
- Don't change the table prefix as a security measure on a live site. It is a common cause of this exact error when done incompletely.
- Don't ignore unknown admin accounts. If you see users you did not create, assume the site may be compromised.
- Don't give your hosting or database login to someone who contacted you out of the blue offering to fix it.
When to get help
If the error covers the whole dashboard and your host cannot restore your administrator role, this needs someone comfortable working directly in the WordPress database. Fixing a table prefix mismatch or restoring a lost admin role is quick for an experienced developer, but a wrong edit can make things worse, so it is worth having it done carefully with a backup taken first. Bring in help immediately if you see unfamiliar admin users or your account was changed without your knowledge — someone should check for a break-in, not just restore access.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does "Sorry, you are not allowed to access this page" mean in WordPress?
WordPress recognizes your login but believes your account does not have permission for the page you requested. It can mean the page no longer exists, or that your account has lost its administrator role.
Why do I get this error after deactivating a plugin?
You are probably still on that plugin's settings page, or following a bookmark to it. Once the plugin is off, the page no longer exists and WordPress shows this message. Go to the main dashboard address and it should load normally.
Why did this error appear after moving my WordPress site?
The most common cause is a table prefix mismatch. The configuration file uses one prefix, but user roles in the database are stored under another, so WordPress cannot find anyone's admin permissions. Fixing the prefix, or the database entries, restores access.
Can a hacker cause this error?
Yes. Attackers sometimes demote or delete the owner's administrator account after creating their own. If you see admin users you do not recognize, treat the site as hacked and get it checked, not just unlocked.
Will resetting my password fix it?
Usually not. This error means WordPress knows who you are but thinks you lack permission. A password reset proves your identity again but does not restore a missing administrator role.
Can my web host fix this for me?
Often, yes. Many hosts can check your user role in the database or create a new administrator account from their control panel. It is a reasonable first request to make.