Locked out of WordPress admin

PlatformWordPress Doing it yourself10 to 40 minutes Checked

The short answer

Work out which lock it is. A forgotten password, a security plugin lockout, a moved login page and a lost two-factor device each have a safe way back. If your own user has gone, or you see admins you do not know, treat it as a hack.

Is this your problem?

  • The password reset email never arrives
  • "Too many failed login attempts" or a lockout message
  • wp-login.php shows a 404 page
  • Two-factor codes are no longer accepted
  • Your username no longer exists

What usually causes it

1
The site cannot send email

How to tell: The reset form says an email was sent, but nothing arrives, even in spam.

2
A security plugin lockout

How to tell: A message about too many attempts, often with a time limit.

3
The login address was moved by a plugin

How to tell: wp-login.php shows a 404, and someone installed a "hide login" plugin.

4
A lost two-factor device

How to tell: You changed phones, or the app was deleted.

5
Your account was changed or deleted

How to tell: Your user is missing, or its role is no longer Administrator.

Before you touch anything

  • Make sure you have your hosting login. Most ways back in go through the host.

How to fix it, step by step

  1. 1

    Wait out a lockout

    Security plugins usually unlock after a set time. If you cannot wait, rename that plugin folder in wp-content/plugins, log in, rename it back and turn it on again.

  2. 2

    Find a moved login page

    Rename the hide-login plugin folder and the normal yoursite.com/wp-login.php works again.

  3. 3

    Set a new password with WP-CLI

    Many hosts include WP-CLI over SSH. This is the cleanest way to set a password.

    wp user list --role=administrator
    wp user update USERNAME --user_pass="a-long-new-password"
  4. 4

    Or with phpMyAdmin

    In phpMyAdmin, open the users table (wp_users, or your own prefix), edit your user, set the MD5 function on user_pass and type a new password. WordPress accepts it once and upgrades it to a stronger hash when you log in.

  5. 5

    Get past two-factor

    Use a backup code if you saved one. If not, rename the two-factor plugin folder, log in, set it up again on your new phone, and turn it back on.

  6. 6

    Fix email for next time

    If the reset email never arrived, the site cannot send mail. Fix that next, or the next lockout will be the same.

Stop and get help if

  • Your user is gone, or there are administrators you do not know. Change the hosting password first, then clean the site.
  • The database users table looks different from what you expect.
Fix it for me

Stop it happening again

  • Store the hosting login and backup codes in a password manager.
  • Keep one spare administrator account with a strong password.
  • Make sure the site can send email.

Questions people ask

How long does a WordPress lockout last?

WordPress itself has no lockout. Security plugins do, and each sets its own time, often 20 minutes to a few hours.

Is MD5 safe to use here?

Only as a one-time step. WordPress replaces it with its own stronger hash the first time you log in.

Still broken? We can fix it.