Why is there an unknown administrator on my WordPress site?

Found an administrator account you do not recognize in WordPress? Learn the harmless explanations, when to treat it as a hack and why not to just delete it.

Open a support ticket

You open the list of users in WordPress and find an administrator you have never seen before. The name may look random, look like a generic word such as "support" or "admin2", or even look almost like the name of someone you know.

An administrator in WordPress can do almost anything: install plugins, edit code, create other users, change content and read customer data. So an unknown administrator deserves attention straight away.

It is not always a hack. There are a few ordinary explanations, and they are worth ruling out first. But if nobody can account for the user, it is safer to treat the situation as a security incident.

The most important advice is simple: do not just delete the account and move on. Deleting it removes the visible sign, but not the way the account was created, and it can destroy information that shows what happened.

This guide explains how to check whether the account is legitimate, what to do if it is not, and which mistakes to avoid.

What does an unknown administrator mean?

It means an account exists with full control of your website, and nobody in your organization currently knows who it belongs to.

There are two possibilities:

  • the account was created legitimately, but nobody remembers or documented it
  • the account was created by someone without permission, usually after exploiting a weakness

The goal of the first checks is to tell these apart as quickly as possible.

Could there be a harmless explanation?

Yes. Before assuming a compromise, check the most common legitimate sources.

A web agency or developer

Agencies, freelancers and developers often create their own administrator account when they start work. If you have worked with anyone on the website, even years ago, the account may be theirs. Ask them.

Your hosting provider

Some hosting providers and managed WordPress services create an account for their support team or for automated tasks. The name or email address often refers to the provider.

A plugin or service

Some plugins and external services create a user when they are connected, for example for backups, monitoring, security or migrations. The email address may belong to the service's domain.

A colleague

Someone in your organization may have created an account for a new team member, a consultant or for testing, without telling anyone.

How to check

Look at the account details:

  • the email address: does it belong to a person or company you know?
  • the registration date: does it match a project, a migration or a new team member?
  • the name: does it match a supplier or a plugin you use?

Then ask the people who could have created it. If you get a clear answer, document it, and consider whether the account is still needed. Old accounts that nobody uses are a risk, even when legitimate.

When should you treat it as a compromise?

Treat the account as malicious if:

  • nobody can explain it after a reasonable check
  • the email address is from a free or random-looking domain unrelated to your business
  • the account was created recently, with no matching project
  • the name imitates a real user or a generic term
  • other warning signs are present, such as spam pages, redirects, unfamiliar plugins or a warning from Google
  • the account reappears after being deleted

Attackers often create an administrator immediately after exploiting a vulnerable plugin, so they can return later even if the vulnerability is fixed.

Why should you not just delete the account?

Deleting the user feels like the natural fix, but on its own it causes three problems.

It does not close the way in

The account was created through some route: a vulnerable plugin, a stolen password, a backdoor. If that route is still open, the attacker can create a new account, sometimes within minutes. See why malware keeps coming back for more on this.

It can destroy evidence

The account's details, registration date and activity help establish when and how the website was compromised. Once it is deleted, this information is harder to recover.

It can delete content

When you delete a user in WordPress, you are asked what to do with the content they created. If you choose to delete it, everything attributed to that user is removed. If the account was used to publish spam, that may be what you want. But if it was attributed to a legitimate account by mistake, or if the attacker changed ownership of existing pages, you could remove real content.

What should you do instead?

Follow these steps in order. They contain the problem while keeping the information you need.

1. Record the details

Write down or take a screenshot of:

  • the username, display name and email address
  • the role
  • the registration date
  • any other unknown accounts, including non-administrator ones
  • the date and time you noticed it

2. Preserve a copy of the website

Make a full backup of the files and database as they are now, and store it separately. This is evidence, not a restore point.

3. Remove the account's power

Instead of deleting it immediately, you can change its role to the lowest one, or change its password and email address to values only you control. This stops the account from being used while keeping its record. A technician may prefer to do this directly, so ask if unsure.

4. End all active sessions

Changing a password does not always log out someone who is already signed in. End active sessions for the unknown account, and ideally for every administrator. Changing the WordPress security keys logs everyone out at once.

5. Change passwords

Change the passwords of all administrators, the hosting account, SFTP and the database. Use unique passwords and enable two-factor authentication where possible. Check that the email accounts linked to administrators are secure too.

6. Check what the account did

Look for:

  • posts, pages or products created or changed recently
  • plugins or themes installed around the account's registration date
  • changes to settings, such as the site address or the default role for new users
  • other users created after it
  • new files or code snippets

7. Find the entry point

This is the step that prevents a repeat. Possible routes include a vulnerable plugin or theme, a reused password, a compromised hosting account or a backdoor left from an earlier incident.

8. Delete the account properly

Once the investigation is complete, delete the account. When WordPress asks what to do with its content, choose deliberately: delete it if it is spam, or attribute it to a legitimate user if it is real content.

What else should you check?

Is registration open to everyone?

In Settings → General, check the "Membership" option ("Anyone can register") and the "New User Default Role". If the default role was changed to Administrator, anyone could have registered with full access. This setting is sometimes changed by attackers.

Are there other unknown users?

Attackers do not only create administrators. An Editor or Shop Manager account can also cause damage. Review all roles.

Is the site a WooCommerce shop or membership site?

If the website handles orders, subscriptions or personal data, an unknown administrator may have had access to customer information. This may have legal implications under data protection rules, so involve whoever is responsible for privacy in your organization.

What should you avoid?

Avoid:

  • deleting the account before recording its details
  • deleting the account's content without checking what it is
  • changing only your own password
  • assuming the problem is solved because the account is gone
  • restoring a backup without checking whether the account exists in it
  • sending passwords to colleagues or suppliers by email

When should you ask for support?

Ask for help when:

  • nobody can explain the account
  • there are other signs of compromise
  • the account comes back after being deleted
  • the website handles payments or personal data
  • you cannot log in yourself, or your own account was changed
  • you are not sure how to find what the account did

How D4Hub can help

D4Hub can:

  • check whether the account is legitimate, using its details and the site's history
  • preserve evidence before making changes
  • end sessions, reset keys and secure all access
  • review content, plugins, settings and files changed by the account
  • find and close the entry point
  • search for backdoors and other unknown accounts
  • remove the account and handle its content correctly
  • advise on the next steps if customer data may have been exposed

You can ask for support at any stage, including after the account has already been deleted.

Open a support ticket

For hands-on users: investigating an unknown administrator

These checks are for people comfortable with WP-CLI and SFTP or SSH.

Before you start, take a full backup of the files and database and keep it separate from the live site. Most commands below only read information. The ones that change something are clearly marked.

List all administrators

wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Note the ID of the unknown account. On multisite, also run wp super-admin list. Repeat the first command without --role=administrator to review every user.

Check the account's metadata

wp user meta list <id>

Replace <id> with the account ID. Look at the capabilities, the display preferences and any plugin-specific entries, which can hint at how the account was created.

See the account's active sessions

wp user session list <id>

This shows current login sessions, typically with the login time, the IP address and the browser. Record this before ending the sessions. An unfamiliar IP address with a recent login is a strong sign the account is in use.

End the account's sessions

This command changes data: it logs the user out everywhere.

wp user session destroy <id> --all

To log out every user at once, you can regenerate the security keys in wp-config.php:

wp config shuffle-salts

This also changes data. Everyone, including you, will need to log in again.

Review content created by the account

wp post list --author=<id> --post_type=any --post_status=any --fields=ID,post_title,post_type,post_status,post_date

Then check the most recently changed content on the whole site:

wp post list --post_type=any --post_status=any --orderby=modified --order=DESC --fields=ID,post_title,post_type,post_modified --posts_per_page=30

Review plugins and recent changes

wp plugin list --fields=name,status,version,update

WordPress does not record when a plugin was installed, but the folder dates are a useful hint:

ls -lt wp-content/plugins/

Compare dates with the account's registration date. Also check wp-content/mu-plugins/ and look for code snippet plugins with new entries.

Check registration settings

wp option get users_can_register
wp option get default_role

A default_role of administrator is a serious warning sign.

Delete the account and reassign content

Only after the investigation, this command removes the user and assigns their content to another account:

wp user delete <id> --reassign=<other-id>

Without --reassign, the user's content is deleted. Choose deliberately.

If anything in these results is unclear, stop. D4Hub can review them with you or take over the investigation.

FAQFrequently asked questions

Some legitimate plugins and services create a user when they are connected, usually with an email address from their own domain. A vulnerable or malicious plugin can also create administrators without your knowledge, which is a common attack.

Not necessarily. The account is a symptom. If the way it was created remains open, the attacker can create another one. The entry point must be found and closed.

WordPress asks whether to delete all content belonging to the user or attribute it to another user. With WP-CLI, the --reassign option does the same. If you do not reassign, the content is deleted.

Not always reliably. Ending the user's sessions, or regenerating the WordPress security keys, is the safer way to make sure nobody stays logged in.

Not by default. Active sessions show recent logins, and some security or activity log plugins record logins, but only from the moment they were installed. Hosting access logs can also help.

It depends on what the account could access and on the data protection rules that apply to you. If the site holds customer data, ask whoever handles privacy in your organization, or a legal adviser.

Yes. The investigation is still possible using backups, logs and the state of the website. D4Hub can check how the account was created and whether anything else was left behind.