Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress errorsFix Sorry, You Are Not Allowed to Access This Page

Fix Sorry, You Are Not Allowed to Access This Page

WordPress shows "Sorry, you are not allowed to access this page" when the logged in account does not have the capability WordPress expects for that screen, or when something has disrupted the normal permissions check. The cause may be as simple as using the wrong account, but plugin changes and migrations can also affect access.

The message you might see

Sorry, you are not allowed to access this page.

Different wording, or a file path in the message? Paste it into our free error finder to see which plugin or theme it comes from.

What the WordPress access error means

WordPress controls administration screens through roles and capabilities. Code normally checks whether the current user has a capability such as permission to edit posts, manage users or administer a particular feature. If that check fails, WordPress can refuse access even though you are successfully logged in.

First determine the scope. If you can use most of wp-admin but one plugin or settings page is blocked, the issue may be limited to that feature. If an administrator has suddenly lost access to large parts of the dashboard, investigate the account's role, recent plugin changes and any recent migration or database work.

This message is different from an incorrect password. Resetting the password will not repair damaged capabilities, although password recovery can be necessary if you cannot authenticate far enough to diagnose the permissions problem.

Common causes of not allowed to access this page

The simplest cause is an account with the wrong role. An Editor, Author or custom role will legitimately be blocked from administration functions reserved for higher capabilities.

Role management and security plugins can modify capabilities or restrict administration URLs. A plugin update, configuration change or conflict can therefore remove access to a screen that previously worked. On migrated sites, database prefix changes or incomplete database transfers can also leave user metadata inconsistent with the active installation.

Multisite introduces another distinction because network administration and individual site administration do not have identical permissions. Custom plugins can also perform their own current_user_can() checks and may request an unsuitable capability.

How to recover WordPress admin access safely

  1. Take a full backup of the website files and database before editing files, roles or database records.
  2. Sign out and confirm you are using the intended administrator account. If another known administrator can log in, ask them to check your user role under Users. A second administrator account is also useful for establishing whether the fault affects one user or the whole site.
  3. If the problem began after changing a security or role plugin, disable only the suspected plugin. When the dashboard is inaccessible, use SFTP or the hosting file manager to rename that plugin's directory inside wp-content/plugins. Renaming the folder deactivates it without deleting its files.
  4. If you cannot log in because the password is also unknown, use the normal "Lost your password?" email route first. Never send a password by email or include it in a support ticket.
  5. If shell access and WP-CLI are available, reset the password from the WordPress directory using the official user command:
    wp user update USERNAME --user_pass='NEW-STRONG-PASSWORD'
    Use a fresh strong password and avoid leaving it in shell history where other users can read it.
  6. If WP-CLI is unavailable but you have authorised database access, WordPress documents a phpMyAdmin fallback. Locate the correct users table, edit the affected user_pass field and apply the MD5 function to a fresh temporary password. WordPress accepts that legacy MD5 value for recovery and rehashes the password after a successful login. Change the password again inside WordPress afterwards. Database editing carries real risk, so verify the database and user row before saving.
  7. If authentication works but permissions remain wrong, do not manually invent capability values in the database. Compare the affected account with a working administrator and investigate role plugins, database prefixes and migration history first.

When to stop and get WordPress access help

Stop editing the database if you are unsure which WordPress installation, table prefix or user record you are changing. A password reset is relatively contained, while incorrectly modifying capability metadata can create further access and security problems.

Technical help is appropriate when all administrators are affected, access disappeared after a migration, disabling the suspected security plugin makes no difference, or permissions return incorrectly after being repaired. Those symptoms justify checking database user metadata, custom role code and server logs rather than repeatedly creating new administrators.

Web Support Services offers an Emergency Fix for £249 per incident with a response within 2 working hours. Care plans start from £59 a month for ongoing WordPress support and maintenance.

Common questions

Answers to the questions we hear most about this.

Why am I not allowed to access a WordPress page when I am an administrator?

Your account may no longer have the expected capability, a security or role plugin may be restricting the page, or a migration may have affected user metadata. Confirm that the account still has the Administrator role before changing anything else.

Will resetting my WordPress password fix the not allowed error?

Not if you can already log in. Passwords control authentication, while this error normally concerns authorisation and capabilities. Reset the password only when you also cannot authenticate.

Can I disable a security plugin if it has locked me out of WordPress?

If you have authorised access to the site's files, you can rename that plugin's directory inside wp-content/plugins using SFTP or the hosting file manager. WordPress will treat the plugin as unavailable. Keep a backup first and rename only the plugin you have identified.

Site down or showing an error?

Call us now. Emergency Fix is £149 with a response within 2 working hours, and no fix means no fee.

Get website support