Type something to search...
How to reset a lost WordPress admin password?

How to reset a lost WordPress admin password?

The easiest way to reset a lost WordPress admin password is to click "Lost your password?" on the login screen, enter your username or email, and follow the reset link WordPress emails to you. If that email never arrives, you can reset the password directly in the database with phpMyAdmin, from the command line with WP-CLI, or by adding a short temporary snippet to your theme's functions.php file. Your hosting account usually gives you access to at least one of these methods.

Getting locked out of your own site happens to everyone at some point, whether it's a forgotten password, an old email address, or a site that simply won't send mail. This guide covers every practical way to regain access, explains when to use each one, and finishes with tips to make sure you don't end up locked out again.

Before You Start: Check the Simple Things

Before resetting anything, rule out the common mistakes that look like a forgotten password:

  • Caps Lock and keyboard layout: Passwords are case-sensitive, and a switched keyboard layout can change special characters.
  • Password manager autofill: Your browser or password manager may be filling in an old password, or a password saved for a different site on the same domain.
  • The right site: If you manage several sites, confirm you're on the correct login page, including staging vs. live.
  • Username vs. email: WordPress accepts either on the login form, but a typo in either will fail.
  • Security plugin lockouts: Too many failed attempts may have temporarily blocked your IP address. Wait for the lockout to expire, or try from a different network.

Method 1: Use the "Lost Your Password?" Link

This is the method WordPress is designed around, and it works whenever your site can send email.

  1. Go to the login page: Visit https://yourdomain.com/wp-login.php or https://yourdomain.com/wp-admin/.
  2. Click "Lost your password?": The link sits below the login form.
  3. Enter your username or email address: Use the one attached to your admin account.
  4. Check your inbox: WordPress sends an email with a password reset link. Check spam and promotions folders too.
  5. Set a new password: Click the link, and WordPress generates a strong password for you. You can keep it or type your own, then click "Save Password."

Reset links expire after a period of time (a day by default), and each link can only be used once. If the link doesn't work, request a new one.

Why the Reset Email Doesn't Arrive

If no email shows up after a few minutes, the most common reasons are:

  • The admin email is outdated: The account is attached to an address you no longer use.
  • Your server can't send mail reliably: WordPress uses PHP's mail() function by default, and many hosts restrict it or its messages get flagged as spam.
  • Aggressive spam filtering: Your email provider may silently discard the message.

If your server's email is the problem, an SMTP plugin like WP Mail SMTP or FluentSMTP can fix it once you're back in. For now, use one of the methods below.

Method 2: Reset the Password With phpMyAdmin

If you can log in to your hosting control panel, you can change the password directly in the database. Back up the database first, just in case.

  1. Open phpMyAdmin: In cPanel, go to Databases > phpMyAdmin. Other hosts have a similar link in their database section.
  2. Select your WordPress database: If you're not sure which one, open wp-config.php and check the DB_NAME value.
  3. Open the users table: Click wp_users. Your prefix may be different, such as wpab_users. Check $table_prefix in wp-config.php if you're unsure.
  4. Find your account: Click "Edit" next to your admin username.
  5. Change the password: In the user_pass row, choose MD5 from the "Function" dropdown, and type your new password in the "Value" field.
  6. Save: Click "Go" at the bottom.

You can now log in with the new password. Don't worry about MD5 being a weak hashing algorithm: WordPress recognizes the MD5 hash, accepts it at login, and immediately re-hashes the password with its modern secure hashing. Since WordPress 6.8, passwords are hashed with bcrypt by default.

Using an SQL Query Instead

If you prefer, run this query in the phpMyAdmin "SQL" tab, replacing the password, username, and table prefix:

UPDATE wp_users
SET user_pass = MD5('YourNewStrongPassword')
WHERE user_login = 'your_username';

Log in as soon as possible afterward so WordPress replaces the MD5 hash with a secure one. Also consider clearing your SQL history in phpMyAdmin, since the plain-text password appears in the query.

Updating the Email Address Too

If the password reset email wasn't arriving because your admin email is outdated, fix that while you're in the database:

UPDATE wp_users
SET user_email = 'you@example.com'
WHERE user_login = 'your_username';

Method 3: Reset the Password With WP-CLI

If you have SSH access and WP-CLI installed, this is the cleanest and fastest option. Navigate to your WordPress root folder and list users to find the right account:

wp user list --role=administrator --fields=ID,user_login,user_email

Then set a new password:

wp user update your_username --user_pass='YourNewStrongPassword'

You can use the user ID instead of the username. WP-CLI hashes the password properly, so there's no MD5 step. To avoid leaving the password in your shell history, prefix the command with a space (if your shell is configured to ignore those) or clear the history afterward.

WP-CLI can also generate a random password and email it to the user:

wp user reset-password your_username

That command relies on your site being able to send email, so the update command is more reliable when mail isn't working.

Method 4: Reset the Password via functions.php

If you have file access through SFTP or your host's file manager but not database or SSH access, you can use a temporary code snippet. This method uses WordPress's own wp_set_password() function, which hashes the password securely.

  • Connect via SFTP or file manager: Navigate to wp-content/themes/your-active-theme/.
  • Back up functions.php: Download a copy before editing.
  • Add the snippet: Paste this at the bottom of the file, replacing the username and password:
function sajjad_emergency_password_reset() {
    $user = get_user_by( 'login', 'your_username' );

    if ( $user ) {
        wp_set_password( 'YourNewStrongPassword', $user->ID );
    }
}
add_action( 'init', 'sajjad_emergency_password_reset' );
  • Load the site once: Visit any page on your site. The snippet runs and resets the password.
  • Remove the snippet immediately: Delete the code from functions.php and save. If you leave it in place, it will reset the password on every page load, which also logs you out repeatedly.
  • Log in with the new password.

If your active theme is a block theme without a functions.php file, you can create a temporary must-use plugin instead. Create the file wp-content/mu-plugins/sajjad-reset.php (create the mu-plugins folder if it doesn't exist), add an opening <?php tag followed by the same code, load the site once, and then delete the file.

Method 5: Create a New Admin User

Sometimes it's easier to create a brand-new administrator than to recover an old one, for example if you don't know the original username. Once you're in, you can reset the old account's password from Users > All Users.

With WP-CLI

wp user create newadmin you@example.com --role=administrator --user_pass='YourNewStrongPassword'

With a Temporary Must-Use Plugin

Create wp-content/mu-plugins/sajjad-add-admin.php:

<?php
/**
 * Temporary: creates an admin account. Delete this file after logging in.
 */
function sajjad_create_emergency_admin() {
    $username = 'newadmin';
    $email    = 'you@example.com';
    $password = 'YourNewStrongPassword';

    if ( username_exists( $username ) || email_exists( $email ) ) {
        return;
    }

    $user_id = wp_create_user( $username, $password, $email );

    if ( ! is_wp_error( $user_id ) ) {
        $user = new WP_User( $user_id );
        $user->set_role( 'administrator' );
    }
}
add_action( 'init', 'sajjad_create_emergency_admin' );

Load the site once, log in with the new account, and delete the file straight away. Leaving code that creates admin accounts on your server is a serious security risk.

Method 6: Ask Your Hosting Provider

Many managed WordPress hosts include a one-click login or password reset tool in their dashboard, and some let you create a login link that bypasses the password entirely. If you're not comfortable editing files or databases, contacting support is a perfectly good option. They'll usually need to verify that you own the hosting account.

If you use WordPress.com or a site builder platform built on WordPress, account recovery goes through their own login system rather than your site's database, so use their account recovery tools instead.

What If You've Lost Access to Everything?

If you can't access the WordPress dashboard, the admin email, the hosting account, or SFTP, start with the hosting provider. Your hosting account is the key to everything else. Hosts have account recovery processes that typically involve verifying your identity with billing details or ID. Once you're back into hosting, any of the methods above will work.

If someone else built your site, they may have set up the hosting under their own account. In that case, you'll need them to either give you access or transfer ownership.

What to Do After Regaining Access

Once you're logged in, take a few minutes to secure the account and prevent future lockouts:

  1. Update your email address: Go to Users > Profile and make sure your email is current. Also check the site admin email under Settings > General. WordPress will send a confirmation to the new address before changing the site email.
  2. Fix outgoing email: Install an SMTP plugin and send a test email, so future reset links arrive reliably.
  3. Use a password manager: Store a long, unique password in a tool like Bitwarden or 1Password.
  4. Enable two-factor authentication: Plugins like Two Factor or Wordfence Login Security add a second layer of protection. Keep your backup codes somewhere safe.
  5. Review user accounts: Check Users > All Users for accounts you don't recognize, especially administrators.
  6. Remove any temporary code: Double-check that you deleted any reset snippets or must-use plugins.
  7. Log out other sessions: On your profile page, click "Log Out Everywhere Else" if you suspect someone else may have your old password.

If You Suspect Your Site Was Hacked

If your password was changed without your knowledge, your admin email was replaced, or unknown admin users appeared, treat it as a security incident. Resetting the password isn't enough on its own. You'll also need to regenerate security keys in wp-config.php, scan for malware, and update all plugins and themes. Regenerating keys forces every logged-in user out:

wp config shuffle-salts

FAQ: Resetting a Lost WordPress Admin Password

Your account may be linked to an old email address, the message may be in spam, or your server may not be sending email reliably. Resetting the password through phpMyAdmin or WP-CLI works around all of these.

Yes, as a temporary step. WordPress accepts the MD5 hash once and then re-hashes the password with its secure algorithm the next time you log in, so log in promptly after the change.

Yes. If you have access to your hosting account, you can reset it through phpMyAdmin, WP-CLI, a temporary functions.php snippet, or your host's dashboard tools, none of which require email.

You can log in with your email address instead of your username. If you don't know either, look in the wp_users table in phpMyAdmin or run wp user list to see all accounts.

No. Changing your password logs out your own sessions. To log out every user, regenerate the security keys and salts in wp-config.php.

By default, a reset link is valid for one day and can only be used once. If it has expired, simply request a new one from the login page.

Yes, always. The snippet runs on every page load, so leaving it in place will keep resetting your password and poses a security risk if someone sees the code.


Conclusion

Losing your WordPress admin password is annoying, but it's rarely a real problem. Start with the "Lost your password?" link, and if the email doesn't arrive, choose whichever alternative matches the access you have: phpMyAdmin for hosting panel access, WP-CLI for SSH access, or a temporary snippet if you can only edit files. If all else fails, your hosting provider can help you back in.

Once you're logged in, spend a few minutes making sure it doesn't happen again. Update your email address, set up reliable outgoing mail, store a strong password in a password manager, and turn on two-factor authentication. Those small steps mean the next time you forget a password, recovery takes a minute instead of an afternoon.

Tags :
Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper
How much does it cost to build a WordPress website?

How much does it cost to build a WordPress website?

Building a WordPress website can cost anywhere from roughly the price of a domain and a year of budget hosting, if you do it yourself with free tools

Dive Deeper