What the WordPress access error means
WordPress controls administration screens through roles and capabilities. Code normally checks whether the current user has a capability such as permission to edit posts, manage users or administer a particular feature. If that check fails, WordPress can refuse access even though you are successfully logged in.
First determine the scope. If you can use most of wp-admin but one plugin or settings page is blocked, the issue may be limited to that feature. If an administrator has suddenly lost access to large parts of the dashboard, investigate the account's role, recent plugin changes and any recent migration or database work.
This message is different from an incorrect password. Resetting the password will not repair damaged capabilities, although password recovery can be necessary if you cannot authenticate far enough to diagnose the permissions problem.
Common causes of not allowed to access this page
The simplest cause is an account with the wrong role. An Editor, Author or custom role will legitimately be blocked from administration functions reserved for higher capabilities.
Role management and security plugins can modify capabilities or restrict administration URLs. A plugin update, configuration change or conflict can therefore remove access to a screen that previously worked. On migrated sites, database prefix changes or incomplete database transfers can also leave user metadata inconsistent with the active installation.
Multisite introduces another distinction because network administration and individual site administration do not have identical permissions. Custom plugins can also perform their own current_user_can() checks and may request an unsuitable capability.
How to recover WordPress admin access safely
- Take a full backup of the website files and database before editing files, roles or database records.
- Sign out and confirm you are using the intended administrator account. If another known administrator can log in, ask them to check your user role under Users. A second administrator account is also useful for establishing whether the fault affects one user or the whole site.
- If the problem began after changing a security or role plugin, disable only the suspected plugin. When the dashboard is inaccessible, use SFTP or the hosting file manager to rename that plugin's directory inside wp-content/plugins. Renaming the folder deactivates it without deleting its files.
- If you cannot log in because the password is also unknown, use the normal "Lost your password?" email route first. Never send a password by email or include it in a support ticket.
- If shell access and WP-CLI are available, reset the password from the WordPress directory using the official user command:
Use a fresh strong password and avoid leaving it in shell history where other users can read it.wp user update USERNAME --user_pass='NEW-STRONG-PASSWORD' - If WP-CLI is unavailable but you have authorised database access, WordPress documents a phpMyAdmin fallback. Locate the correct users table, edit the affected user_pass field and apply the MD5 function to a fresh temporary password. WordPress accepts that legacy MD5 value for recovery and rehashes the password after a successful login. Change the password again inside WordPress afterwards. Database editing carries real risk, so verify the database and user row before saving.
- If authentication works but permissions remain wrong, do not manually invent capability values in the database. Compare the affected account with a working administrator and investigate role plugins, database prefixes and migration history first.
When to stop and get WordPress access help
Stop editing the database if you are unsure which WordPress installation, table prefix or user record you are changing. A password reset is relatively contained, while incorrectly modifying capability metadata can create further access and security problems.
Technical help is appropriate when all administrators are affected, access disappeared after a migration, disabling the suspected security plugin makes no difference, or permissions return incorrectly after being repaired. Those symptoms justify checking database user metadata, custom role code and server logs rather than repeatedly creating new administrators.
Web Support Services offers an Emergency Fix for £249 per incident with a response within 2 working hours. Care plans start from £59 a month for ongoing WordPress support and maintenance.