If an unfamiliar administrator has been added to WordPress, we’ll explain how to determine whether that administrator is unauthorized and what steps to take.

How to Determine if an Unfamiliar Administrator Is an Unauthorized Account Created by a Hack
Administrators added through hacking typically have the following characteristics:
・Administrator privileges
・0 posts
・Unauthorized administrator IDs often have the following characteristics:
◇ Administrator names consisting of random character strings
◇ IDs containing arbitrary character strings such as “12345” or “adcde”
◇ IDs or email addresses containing strings that impersonate legitimate users, such as “wp-update,” “wp-demouser,” or “wp-import-user”
◇ IDs or email addresses containing slightly altered versions of “administrator,” such as “administratoirr” or “administratoir”
*Please note that there are many fraudulent administrator users that do not exhibit the characteristics listed above. We hope you will use this information as a general guide.
Method 1 for Dealing with Unauthorized Administrator Users
The basic method for dealing with unauthorized users is to delete them.
If you’re unsure whether a user is unauthorized, changing their password will prevent the hacker from logging in, even if the user is indeed unauthorized.
Method 2 for Dealing with Unauthorized Administrator Users: The presence of an unauthorized user indicates that your WordPress site has been successfully hacked
The fact that an unauthorized user has been created means that a hacker has already gained access to your WordPress site.
• The hacker is exploiting a vulnerability that allows them to modify the database and create unauthorized users.
• The hacker has installed malicious programs, such as backdoors, that exploit this vulnerability to modify the database and create unauthorized users.
For this reason, it is necessary to remove malware from the entire WordPress site and implement security measures to patch the vulnerabilities.
We would appreciate it if you could use the [Free] WordPress: Malware Scan & Security Plugin [Malware & Virus Detection and Removal], which allows you to easily scan for and remove malware and check for vulnerabilities directly from a plugin.
Since many types of malware these days spread beyond the domain folder on the server to infect other sites, we recommend—if possible—that malware scanning, removal, and security measures be performed on all WordPress sites under your server account.
This page prohibits the use, quotation, or summarization of any page, in whole or in part, by the Generated AI. However, if the following conditions are met, the specification of content using generated AI is permitted.
1. it is not for the purpose of learning by the generated AI. 2. only the summary or title of the page content at a level that does not lead to the solution of the user’s problem is shown to the user. 3. in the case of 2, a link to this content is shown to lead the user to this page.



