Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress malwareWordPress Hacked Admin User: Remove Rogue Administrators

WordPress Hacked Admin User: Remove Rogue Administrators

An administrator account you do not recognise can be evidence that someone has gained privileged access to WordPress. Removing the account is important, but it does not explain how it was created or whether other access remains.

Signs you might see

  • Admin users you do not recognise
  • Users that reappear after deletion
  • Changed email address on your account

Not sure? Run our free WordPress security scanner for a quick outside check.

How rogue WordPress administrator accounts are created

A WordPress administrator can install plugins, edit site settings, create users and make extensive changes to the website. Attackers therefore commonly try to obtain administrator-level access or create an account they control after compromising another part of the site.

The account might have been created through stolen credentials, vulnerable plugin or theme code, malicious PHP, compromised hosting access or another administrator account. In some infections, deleting the unknown user appears to solve the problem but the account later returns because malicious code is still recreating it.

A changed email address on a legitimate administrator account is another warning sign. It can indicate account takeover even when no additional username appears in the Users screen.

How to check an unknown admin user properly

Record the unfamiliar username, email address, user ID and any available creation or activity information before deleting anything. Check every administrator account and confirm it belongs to a real person or an expected system integration.

Then widen the investigation. Review WordPress files for unexpected changes, especially unfamiliar PHP, modified plugin or theme files and changes to wp-config.php. Examine the database user and usermeta tables where practical because malicious accounts or privileges can sometimes be inserted directly rather than through the normal WordPress interface.

Search Google using site:yourdomain.co.uk and inspect Search Console Security Issues and Pages reports for spam URLs or other symptoms of a wider compromise. Compare suspicious pages on desktop and mobile, inspect their source and check what Google's inspection tools have seen. Attackers can combine rogue accounts with cloaked SEO spam or redirects.

Our free WordPress security scanner can help identify externally visible problems, but an account compromise also requires direct review of users, files and the database.

How to remove a hacked WordPress admin user safely

  1. Preserve the compromised site first. Take a complete files and database backup and retain an untouched copy for evidence before deleting accounts or changing files.
  2. Confirm the user is unauthorised. Check with legitimate site administrators before removing an unfamiliar account, particularly on sites maintained by several suppliers or teams.
  3. Investigate how it appeared. Look for vulnerable plugins or themes, malicious files, stolen administrator credentials and compromised hosting access. If a rogue user returns after deletion, treat that as evidence that another persistence mechanism remains.
  4. Remove malicious access. Delete confirmed rogue accounts, inspect privileged users and remove malicious code. Replace altered WordPress core files and reinstall compromised extensions from trusted sources where necessary.
  5. Rotate every relevant credential. Change WordPress user passwords, hosting credentials, database passwords, FTP or SFTP credentials and exposed keys. Replace the salts in wp-config.php to invalidate existing WordPress sessions.
  6. Verify the cleanup. Recheck administrator accounts, scan files and database content and confirm that the vulnerability or stolen access used to create the account has been closed.

Hacked Site Rescue is £349 fixed price for malware removal, clean restoration, backdoor checks and post-cleanup hardening.

How to prevent unknown WordPress admins returning

Keep WordPress and its extensions updated and remove plugins and themes that are no longer required. Protect every privileged account with a unique password and two-factor sign-in, and avoid giving administrator access to users who only need to edit content.

Periodically review the administrator list rather than treating it as a one-off task. File integrity monitoring and security logs can make unexplained changes easier to investigate, particularly after a previous compromise.

Maintain current off-server backups so recovery does not depend on a copy stored inside the same hosting account. Care plans start from £59 a month and include weekly updates, daily off-server backups, 24/7 uptime monitoring and security scanning.

Common questions

Answers to the questions we hear most about this.

I found an unknown admin user in WordPress. Does that mean the site is hacked?

It is a serious indicator but should be verified before deletion because developers, agencies and some legitimate systems may have administrator accounts. If nobody authorised the account, investigate the site as a potential compromise.

Why does a deleted WordPress administrator keep coming back?

Malicious code, a backdoor or another compromised privileged account may be recreating it. Removing the user repeatedly will not solve the underlying problem until that persistence mechanism is found.

Should I change every password after finding a rogue administrator?

Change all credentials that could provide access to the compromised site, including WordPress accounts, hosting, database and FTP or SFTP credentials, as well as relevant keys. WordPress salts should also be replaced to invalidate existing sessions.

Think your site has been hacked?

Hacked Site Rescue is a fixed £249. We remove the malware, close the way in and help clear the warnings.

Get website support