How to Remove Unauthorized Administrator Access in WordPress: 20 Steps

Discovering an unfamiliar Administrator account on your WordPress website can be alarming.

An unexpected Administrator may be the result of a forgotten account, a former developer, an incorrectly assigned role, or a security incident.

Whatever the cause, unexpected administrative access should not be ignored.

An Administrator has extensive control over a WordPress website. Depending on the site’s configuration, an Administrator may be able to manage users, install plugins, modify themes, change settings, and alter website content.

If you find an Administrator account that should not have access, the priority is to verify the account, secure legitimate administrators, remove or reduce unauthorized access, and investigate how the access appeared.

This guide explains how to safely handle unauthorized Administrator access in WordPress.


What Is Unauthorized Administrator Access?

Unauthorized Administrator access exists when someone has administrative privileges without legitimate authorization.

This can include:

  • An unknown Administrator account
  • A former employee who still has Administrator access
  • A former contractor with unnecessary privileges
  • A user who was incorrectly upgraded
  • A compromised account
  • An Administrator account created without approval
  • A legitimate user whose role was unexpectedly changed

Not every unfamiliar Administrator is necessarily an attacker.

However, unknown administrative access should always be investigated before being dismissed.


Why Unauthorized Administrator Access Is Serious

Administrator privileges provide extensive control over a WordPress website.

An unauthorized Administrator may potentially be able to:

  • Modify website content
  • Create additional users
  • Change user roles
  • Install plugins
  • Activate or deactivate plugins
  • Modify themes
  • Change important settings
  • Upload files
  • Alter website functionality
  • Access sensitive administrative information

The exact capabilities depend on the WordPress environment, plugins, custom code, and hosting configuration.

The important point is that administrative access should be limited to people who genuinely need it.

For broader guidance, see WordPress Administrator Security.


Before Removing an Administrator: Verify the Account

Don’t immediately delete an unfamiliar account without first determining what it is.

An unexpected account could belong to:

  • A website owner
  • A developer
  • A hosting provider
  • A previous agency
  • A legitimate employee
  • A maintenance service
  • A forgotten administrator

Check:

  • Username
  • Display name
  • Email address
  • Registration information
  • Assigned role
  • User activity
  • Who created or authorized the account, if known

If the account is legitimate, reducing or deleting it could disrupt the website.


Step 1: Make a List of All Administrators

Start by reviewing the WordPress user list.

Identify every account with administrative privileges.

Create a simple inventory:

User Role Known User? Access Required?
Owner Administrator Yes Yes
Developer Administrator Yes Temporary
Former contractor Administrator Yes No
Unknown account Administrator No Investigate

This gives you a clear picture of the administrative access currently present.

For a more comprehensive approach, see How to Audit WordPress User Roles.


Step 2: Identify the Unauthorized Account

Look for indicators that an Administrator may not be legitimate.

Potential warning signs include:

  • An unfamiliar username
  • An unfamiliar email address
  • An account nobody on the team recognizes
  • An unexpected role change
  • A recently created Administrator account
  • Multiple unexpected Administrator accounts
  • An Administrator created after a security problem
  • A former user who should no longer have access

One suspicious account doesn’t automatically prove that the website has been compromised.

But it does justify further investigation.


Step 3: Confirm That the Account Is Truly Unauthorized

Before removing the account, contact the relevant website owner or administrator.

Ask:

Who created this account?

Why does it have Administrator access?

Is this person currently working on the website?

Does this account still need administrative privileges?

This is particularly important for agencies and websites with multiple stakeholders.

A developer’s account might look unfamiliar to a new website manager but still be legitimate.


Step 4: Protect Legitimate Administrator Accounts

If you suspect unauthorized access, secure the legitimate administrators before making major changes.

Review legitimate Administrator accounts for:

  • Strong unique passwords
  • Appropriate authentication
  • Current contact information
  • Correct roles
  • Unnecessary additional capabilities
  • Unknown sessions or activity where available

If an existing Administrator account may itself be compromised, changing its credentials should be part of the response.

Don’t assume that deleting one suspicious account automatically resolves the problem.


Step 5: Remove the Unauthorized Administrator Through WordPress

If you have confirmed that an Administrator account is unauthorized and you still have legitimate administrative control, you can remove it through the WordPress dashboard.

Before deletion, consider whether the account owns any content.

If it has authored posts or other content, WordPress may provide options for handling that content when deleting the user.

Choose the appropriate content-management option rather than accidentally losing important material.

The goal is to remove the account without unnecessarily affecting legitimate website data.


Step 6: Consider Downgrading Instead of Deleting

Not every excessive Administrator account needs to be deleted.

For example, a legitimate writer may have been incorrectly given Administrator access.

In that situation, the appropriate action may be to change the account to:

  • Editor
  • Author
  • Contributor
  • Subscriber
  • A suitable custom role

The correct role depends on the user’s responsibilities.

This follows the principle of least privilege.

See [Principle of Least Privilege in WordPress].


Step 7: Review Other User Accounts

If you discover one unauthorized Administrator, don’t stop there.

Review the entire user list.

Look for:

  • Additional unexpected Administrators
  • New Editor accounts
  • Suspicious Authors
  • Unknown Contributors
  • Duplicate accounts
  • Inactive accounts
  • Accounts with unusual email addresses

An unauthorized Administrator may not be the only problematic account.


Step 8: Check for Newly Created Accounts

Unexpected account creation can be an important clue.

Look for users that appeared around the same time as:

  • Suspicious website activity
  • Unexpected content changes
  • Plugin changes
  • Theme changes
  • Password-reset notifications
  • Other security events

Document anything unusual before making extensive changes.

This information may help determine how the account appeared.


Step 9: Review Recent Role Changes

An unauthorized account isn’t the only problem to look for.

A legitimate user may have been upgraded unexpectedly.

For example:

Author → Administrator

or

Editor → Administrator

If nobody authorized the change, investigate it.

Unexpected privilege changes can result from:

  • Human error
  • Poor access management
  • Plugin behavior
  • Custom code
  • Account compromise

This is why a user-role audit should examine both accounts and role assignments.


Step 10: Review Plugin and Theme Changes

If unauthorized administrative access is suspected, review recent changes to the website.

Pay particular attention to:

  • Newly installed plugins
  • Unexpected plugins
  • Recently modified plugins
  • Unknown themes
  • Unexpected theme changes
  • Custom code changes

A malicious or compromised Administrator may attempt to maintain access through website components.

However, an unexpected plugin or theme does not automatically prove malicious activity. Investigate before drawing conclusions.


Step 11: Review Website Activity

Look for unusual activity around the time the unauthorized access appeared.

Depending on your available logging and monitoring tools, investigate:

  • User creation
  • Role changes
  • Plugin installation
  • Plugin activation
  • Theme changes
  • Content modifications
  • Settings changes
  • Login activity

Keep records of relevant findings.

If you suspect a serious compromise, preserve available evidence before making extensive changes whenever possible.


Step 12: Change Credentials If a Compromise Is Suspected

If there is evidence that an account was compromised, simply deleting the suspicious Administrator may not be enough.

Review and secure credentials for legitimate privileged users.

Use:

  • Strong unique passwords
  • Multi-factor authentication where available
  • Individual accounts
  • Secure password management
  • Updated recovery information

Do not reuse passwords across WordPress and other services.


Step 13: Review Other Access Outside WordPress

WordPress Administrator access may not be the only access that needs attention.

If you believe the website was compromised, review access to:

  • Hosting
  • Domain management
  • SFTP
  • SSH
  • Database management
  • CDN services
  • Analytics platforms
  • Search platforms
  • Third-party plugins
  • Email accounts
  • Backup systems

An attacker who obtained access through another system may potentially regain WordPress access even after a suspicious user is removed.


Step 14: Check for Persistence

One of the biggest mistakes is assuming:

“I deleted the unauthorized Administrator, so the problem is solved.”

If unauthorized access resulted from a compromise, the person or malicious software may have created another way to regain access.

Look for:

  • Additional unknown accounts
  • Unexpected plugins
  • Suspicious custom code
  • Modified files
  • Unknown scheduled tasks
  • Unexpected API integrations
  • Other unusual configuration changes

For serious incidents, consider getting professional security assistance rather than relying solely on deleting a user.


Step 15: Review Custom Roles and Capabilities

Don’t limit the investigation to the Administrator role.

Custom roles may contain powerful capabilities.

A user could potentially have substantial access without being labeled “Administrator.”

Review:

  • Custom roles
  • Custom capabilities
  • Plugin-specific roles
  • Plugin-specific capabilities

For more information, see [Custom WordPress Roles] and [WordPress Capabilities Explained].


Step 16: Remove Unnecessary Administrator Privileges

Once legitimate users have been identified, reduce unnecessary administrative access.

For example:

User Before After
Owner Administrator Administrator
Content manager Administrator Editor
Writer Administrator Author
Guest writer Administrator Contributor
Developer Administrator Temporary Administrator when required

This creates a more controlled permission structure.


Step 17: Review Former Employees and Contractors

Former team members are a common source of unnecessary access.

A person may have legitimately received Administrator access during their employment or project.

But after the relationship ends, the access may no longer be appropriate.

Review accounts belonging to:

  • Former employees
  • Former freelancers
  • Former developers
  • Former agencies
  • Former consultants

Then remove or reduce access as appropriate.


Step 18: Enable Additional Protection for Administrators

Once the user list has been cleaned up, strengthen the remaining privileged accounts.

Consider:

  • Strong unique passwords
  • Two-factor authentication
  • Login monitoring
  • Security alerts
  • Individual accounts
  • Regular access reviews

The objective is to make unauthorized administrative access harder to obtain and easier to detect.


Step 19: Keep WordPress and Plugins Updated

If unauthorized access resulted from a vulnerability, outdated software may be relevant.

Review the versions of:

  • WordPress
  • Plugins
  • Themes

Keep supported software appropriately updated.

Updates are only one part of security, but they are an important component of maintaining a secure WordPress environment.


Step 20: Review Backups

Maintain reliable backups of your website.

Backups can be particularly important when investigating or recovering from a security incident.

A good backup strategy should consider:

  • Website files
  • Database
  • Configuration
  • Backup frequency
  • Backup storage
  • Restoration procedures

Don’t assume that a backup is useful simply because it exists.

Test restoration procedures periodically.


What If You Cannot Access the WordPress Dashboard?

If an unauthorized Administrator has taken control and you can no longer access your legitimate account, the situation is different.

Don’t repeatedly guess passwords or make random database changes.

Instead:

  1. Secure the associated email account.
  2. Secure hosting and other administrative accounts.
  3. Contact your hosting provider if appropriate.
  4. Preserve relevant logs and evidence.
  5. Use a trusted recovery procedure.
  6. Consider professional WordPress security assistance if compromise is suspected.

The exact recovery process depends on how access was lost and what systems you still control.


Should You Delete an Unauthorized Administrator Immediately?

Not always.

If you have confirmed the account is unauthorized and you have preserved the information needed for investigation, removal may be appropriate.

But if you suspect a broader compromise, first consider:

  • What created the account?
  • Are there other unauthorized users?
  • Has another legitimate account been compromised?
  • Were plugins or themes modified?
  • Are there suspicious files?
  • Is the hosting account secure?

Deleting one account without investigating the underlying cause may leave the real problem unresolved.


Unauthorized Administrator Access vs Excessive Administrator Access

These situations are different.

Excessive access

A legitimate user has more permissions than necessary.

Example:

A writer has Administrator access even though they only need to publish their own posts.

The solution may be to reduce the user’s role.

Unauthorized access

A person or account should not have access at all.

Example:

An unknown user has been granted Administrator privileges without authorization.

The response may require removal, credential protection, investigation, and potentially incident response.

Understanding the difference helps you choose the appropriate response.


Common Mistakes When Removing Unauthorized Access

Only deleting one suspicious account

There may be other unauthorized access mechanisms.

Ignoring legitimate Administrator accounts

If a legitimate account is compromised, the problem may continue.

Forgetting hosting access

WordPress is not the only possible entry point.

Not reviewing plugins

Unexpected software changes can be important clues.

Removing users without considering their content

User deletion can affect content ownership and attribution.

Immediately reinstalling everything without investigation

In a serious incident, preserving evidence can help determine what happened.

Assuming the problem is solved after changing one password

A compromise can involve more than one account.


How to Prevent Unauthorized Administrator Access

The best response is prevention.

Limit Administrator accounts

Only users who genuinely need broad administrative access should receive it.

Use individual accounts

Avoid shared administrative credentials.

Apply least privilege

Give users only the access required for their responsibilities.

Review users regularly

Audit Administrator accounts and other privileged users.

Protect privileged accounts

Use strong authentication and additional security controls where appropriate.

Remove former users

Don’t leave unnecessary accounts active.

Review temporary access

Remove elevated permissions after projects end.

Monitor important changes

Watch for unexpected user creation and role changes.

For a broader security strategy, see [WordPress User Roles Security Guide].


WordPress Unauthorized Administrator Checklist

Use this checklist if you discover an unexpected Administrator.

Immediate review

  • Identify all Administrator accounts.
  • Confirm which administrators are legitimate.
  • Identify the suspicious account.
  • Document its username and email.
  • Check when the account appeared if information is available.
  • Review recent role changes.

Account security

  • Secure legitimate Administrator accounts.
  • Change credentials where compromise is suspected.
  • Enable additional authentication where appropriate.
  • Avoid shared accounts.

Investigation

  • Review other user accounts.
  • Check for unexpected plugins.
  • Check for unexpected themes.
  • Review relevant activity logs.
  • Check hosting access.
  • Review other privileged services.
  • Look for additional persistence mechanisms.

Cleanup

  • Remove confirmed unauthorized accounts.
  • Reduce excessive legitimate privileges.
  • Remove unnecessary temporary access.
  • Review former users.
  • Document what was changed.

Prevention

  • Apply least privilege.
  • Audit users periodically.
  • Keep WordPress updated.
  • Keep plugins and themes updated.
  • Maintain reliable backups.
  • Review privileged access regularly.

Example: Removing Excessive Administrator Access

Imagine your website has four users:

User Current Role Situation Recommended Action
Owner Administrator Needs full access Keep
Editor Administrator Manages content Consider Editor
Writer Administrator Publishes own posts Consider Author
Unknown account Administrator No known owner Investigate and remove if unauthorized

Notice that the Editor and Writer aren’t necessarily unauthorized.

They may simply be overprivileged.

The unknown account is different because its authorization is unclear.

This distinction is essential when auditing WordPress access.


Frequently Asked Questions

How do I remove an unauthorized Administrator in WordPress?

First confirm that the account is not legitimate. If you have legitimate administrative access, review the account and remove it through the appropriate WordPress user-management process. If you suspect a broader compromise, investigate other accounts, credentials, plugins, themes, and hosting access as well.

Should I immediately delete an unknown WordPress Administrator?

Not necessarily. First verify that the account is genuinely unauthorized and document relevant information. If a compromise is suspected, investigate whether other unauthorized access exists.

What if an employee has Administrator access but no longer needs it?

If the employee is still authorized to use the website, reduce the account to a role appropriate for their current responsibilities rather than necessarily deleting the account.

What if a former developer still has Administrator access?

If the developer no longer requires access, remove or reduce their WordPress privileges and review any other access they may have to hosting, domains, databases, or third-party services.

Can an unauthorized Administrator create another Administrator?

Yes. A user with sufficient privileges may be able to create or modify other accounts. That’s why finding one unexpected Administrator should trigger a broader user review.

Can plugins create Administrator accounts?

Plugins can interact with WordPress users and capabilities, but an unexpected Administrator should not automatically be blamed on a plugin. Investigate the site’s configuration, plugin behavior, activity records, and other evidence.

What should I do if I lost Administrator access?

Secure your associated email, hosting, and other administrative accounts, then use a trusted recovery process or contact your hosting provider. If you suspect compromise, consider professional security assistance.

How can I prevent unauthorized Administrator access?

Limit Administrator privileges, use individual accounts, protect privileged credentials, apply least privilege, review users regularly, remove unnecessary access, and keep WordPress and extensions appropriately maintained.


Final Thoughts

An unexpected WordPress Administrator should never be treated as a minor user-management issue.

First determine whether the account is legitimate.

Then review the rest of the user list.

Secure legitimate privileged accounts.

Remove confirmed unauthorized access or reduce excessive privileges.

Finally, investigate how the access appeared and whether anything else on the website was changed.

The most important lesson is this:

Removing an unauthorized Administrator is only the first step if a compromise is suspected.

You also need to determine whether another account, plugin, credential, or system could allow the unauthorized party to return.

For long-term protection, combine regular role audits with the principle of least privilege, strong authentication, software maintenance, backups, and ongoing access reviews.


Discover more from WORDPRESS ROLE

Subscribe to get the latest posts sent to your email.

Discover more from WORDPRESS ROLE

Subscribe now to keep reading and get access to the full archive.

Continue reading

security verification.