How to regain access to WordPress admin
Methods for getting back into your WordPress dashboard when locked out, including resetting passwords via email, phpMyAdmin or WP-CLI, creating new admin users, disabling security plugins and fixing URL mismatches.
Getting locked out of your WordPress dashboard is one of the most common problems site owners run into. You try to log in at /wp-admin or /wp-login.php and either you've forgotten the password to the only admin account, the page redirects in a loop because of a site error, or a security plugin has blocked you by mistake.
WordPress stores its users in a database that you can reach without the dashboard, through your hosting account. So there's almost always a way back in, even if you've lost your only admin account.
Common reasons you can't log in
Before jumping into fixes, it helps to work out what's actually going wrong. Most lockouts fall into one of these categories:
- Forgotten or changed password. The most common cause, especially if the site hasn't been touched for a while.
- A security plugin blocking you. Many security plugins lock out an IP address after a number of failed login attempts, or move the login page to a custom address.
- Deleted or damaged admin account. If the only administrator has been removed, there's no account to log in with.
- Mismatched site addresses. After a domain change or migration, WordPress can get stuck in a redirect loop if the addresses stored in its settings don't match the address you're visiting.
- Cookies or browser cache. Occasionally, old cookies or a cached redirect stop the login page from working.
Work through the sections below in order, starting with the simplest fix.
Clear cookies and try a private window
This is worth trying first, especially if the login page won't load or keeps redirecting.
Clear your browser cookies for the site's domain (not all your browsing data), or try logging in from a private or incognito window. If that works, the problem was in your browser rather than on the site.
Reset your password by email
This is the quickest fix and doesn't need any technical access.
On the login page, click Lost your password? and enter your username or email address. WordPress emails a reset link to the address on that account.1
If the email doesn't arrive, check your spam folder. Some hosting setups stop WordPress sending email at all. If that's the case, move on to the methods below, and once you're back in, see our guide to fixing WordPress email delivery so password resets work next time.
Reset your password with phpMyAdmin
If email isn't working, you can set a new password directly in the database using phpMyAdmin, a database tool most hosts include in their control panel.
Before changing anything, export a copy of your database from phpMyAdmin's Export tab (or use your host's backup tool). Editing the wrong row or table can break the site, and the export is your way back.
- Log in to your hosting control panel and open phpMyAdmin.
- Select your WordPress database. If you're not sure which one belongs to your site, the
DB_NAMEvalue in yourwp-config.phpfile tells you. - Open the
wp_userstable. Your table prefix may not bewp_. The$table_prefixvalue inwp-config.phptells you what it is. - Find your username and click Edit.
- In the
user_passfield, choose MD5 from the function dropdown and type your new password in the value box. - Click Go to save.
You can now log in with the new password. Choosing MD5 matters, since typing a plain password into that field won't work. MD5 is an old, weak way of storing passwords, but WordPress accepts it for this purpose and automatically replaces it with a stronger hash the first time you log in.23
If you have SSH access and WP-CLI (a command-line tool for managing WordPress), you can reset the password from the command line instead:4
wp user update your_username --user_pass="your_new_password"
Commands you type are often saved in your shell history, so change the password again from the dashboard once you're in.
Create a new admin user
If the only admin account has been deleted, you'll need to create a new one. WP-CLI is the simplest and safest way:4
wp user create newadmin [email protected] --role=administrator --user_pass="your_password"
Without WP-CLI, it's possible to create an admin by adding rows to the database in phpMyAdmin, but it's easy to get wrong. You'd add a row to wp_users (with MD5 chosen for user_pass), then two rows to wp_usermeta for that user's ID: wp_capabilities set to a:1:{s:13:"administrator";b:1;} and wp_user_level set to 10, using your own table prefix in place of wp_ throughout. A mistake in these values can leave the account without access or cause errors, so take a database backup first. If you're not confident, this is a job for your host or a developer.
If you find admin accounts you don't recognise, or your own account has disappeared without explanation, your site may have been compromised. See our guide to cleaning up a hacked WordPress site.
Disable a security plugin that's blocking you
Security plugins can lock you out after repeated failed login attempts, or by moving the login page. If you think a plugin is the cause, you can deactivate it without the dashboard.
Connect to your site via SFTP or your hosting file manager and go to wp-content/plugins/. Find the security plugin's folder and rename it, for example from plugin-name to plugin-name-disabled. WordPress can no longer load the plugin, so it's effectively switched off.
This also switches off the protection that plugin provides, so don't leave it like this. Once you're logged back in, rename the folder back to its original name, check it's active again under Plugins and adjust its lockout or allowlist settings so you don't get blocked again. If you see a "403 Forbidden" page rather than a login screen, see our guide to the 403 error.
Fix mismatched site addresses
After a domain change or migration, WordPress can get stuck in a redirect loop if the two addresses stored in its settings (the WordPress Address and Site Address) don't match the address you're visiting. This is common after moving a site to a new domain or switching between http and https. Our guides to fixing redirect loops and moving to HTTPS without mixed content cover the wider fix.
You can override these addresses in wp-config.php. Download a copy of the file first, since a typo in it can take the whole site offline. Then add the following just above the line that reads /* That's all, stop editing! */:
define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );
Replace https://example.com with your actual address. Make sure it matches how your site is actually served: use https:// only if your site has a working SSL certificate, and include www. only if your site uses it.
These lines override the addresses stored in the database without changing them,5 and while they're in place the address fields under Settings → General are greyed out.6 So you can't correct the database values from that screen at the same time. The simplest option is to leave the lines in place, which is a perfectly normal setup. If you'd rather remove them later, the stored values need correcting first (for example with WP-CLI's wp option update home and wp option update siteurl commands, after a database backup), otherwise the loop will come back when the lines are removed. If you're not sure, leave them in.
Still locked out?
If none of these methods have worked, or you're not comfortable editing your database or site files, my WordPress development service and emergency WordPress support can get you back in. Your hosting provider may also be able to help, since they have direct access to your files and database.
Reset your password, WordPress.org Documentation. ↩
Your password, WordPress Advanced Administration Handbook. ↩
WordPress 6.8 will use bcrypt for password hashing, Make WordPress Core, 17 February 2025. ↩
wp-config.php, WordPress Advanced Administration Handbook. ↩
options-general.php, WordPress source code on GitHub. ↩