How rogue WordPress administrator accounts are created
A WordPress administrator can install plugins, edit site settings, create users and make extensive changes to the website. Attackers therefore commonly try to obtain administrator-level access or create an account they control after compromising another part of the site.
The account might have been created through stolen credentials, vulnerable plugin or theme code, malicious PHP, compromised hosting access or another administrator account. In some infections, deleting the unknown user appears to solve the problem but the account later returns because malicious code is still recreating it.
A changed email address on a legitimate administrator account is another warning sign. It can indicate account takeover even when no additional username appears in the Users screen.
How to check an unknown admin user properly
Record the unfamiliar username, email address, user ID and any available creation or activity information before deleting anything. Check every administrator account and confirm it belongs to a real person or an expected system integration.
Then widen the investigation. Review WordPress files for unexpected changes, especially unfamiliar PHP, modified plugin or theme files and changes to wp-config.php. Examine the database user and usermeta tables where practical because malicious accounts or privileges can sometimes be inserted directly rather than through the normal WordPress interface.
Search Google using site:yourdomain.co.uk and inspect Search Console Security Issues and Pages reports for spam URLs or other symptoms of a wider compromise. Compare suspicious pages on desktop and mobile, inspect their source and check what Google's inspection tools have seen. Attackers can combine rogue accounts with cloaked SEO spam or redirects.
Our free WordPress security scanner can help identify externally visible problems, but an account compromise also requires direct review of users, files and the database.
How to remove a hacked WordPress admin user safely
- Preserve the compromised site first. Take a complete files and database backup and retain an untouched copy for evidence before deleting accounts or changing files.
- Confirm the user is unauthorised. Check with legitimate site administrators before removing an unfamiliar account, particularly on sites maintained by several suppliers or teams.
- Investigate how it appeared. Look for vulnerable plugins or themes, malicious files, stolen administrator credentials and compromised hosting access. If a rogue user returns after deletion, treat that as evidence that another persistence mechanism remains.
- Remove malicious access. Delete confirmed rogue accounts, inspect privileged users and remove malicious code. Replace altered WordPress core files and reinstall compromised extensions from trusted sources where necessary.
- Rotate every relevant credential. Change WordPress user passwords, hosting credentials, database passwords, FTP or SFTP credentials and exposed keys. Replace the salts in wp-config.php to invalidate existing WordPress sessions.
- Verify the cleanup. Recheck administrator accounts, scan files and database content and confirm that the vulnerability or stolen access used to create the account has been closed.
Hacked Site Rescue is £349 fixed price for malware removal, clean restoration, backdoor checks and post-cleanup hardening.
How to prevent unknown WordPress admins returning
Keep WordPress and its extensions updated and remove plugins and themes that are no longer required. Protect every privileged account with a unique password and two-factor sign-in, and avoid giving administrator access to users who only need to edit content.
Periodically review the administrator list rather than treating it as a one-off task. File integrity monitoring and security logs can make unexplained changes easier to investigate, particularly after a previous compromise.
Maintain current off-server backups so recovery does not depend on a copy stored inside the same hosting account. Care plans start from £59 a month and include weekly updates, daily off-server backups, 24/7 uptime monitoring and security scanning.