My WordPress site was hacked and I can’t log in! Here’s a step-by-step guide on how to regain access when both the admin password and email address have been changed.

When a Hacker Takes Over Your WordPress Admin Account

Although this is a rare occurrence, hackers may not only add unauthorized users to WordPress but also change the password or email address of an existing administrator, preventing you from logging in with your original credentials.
Here’s how to regain administrator access and log in again.

1. Upload database connection software to the server

Download a database connection program called Adminer.

Download: https://github.com/vrana/adminer/releases/download/v6.1.1/adminer-6.1.1-en.php

Use FTP software to upload this file to the WordPress root directory.
While you’re at it, please download the file named `wp-config.php`, which should be located in the WordPress root directory (we’ll use this file to check the database connection settings).

*Please refer to the help section of your hosting provider for instructions on how to connect via FTP.

2. Access the database connection software and log in

Next, access the database connection software you just uploaded via your browser.

Example URL:

https://WordPress site URL/adminer-6.1.1-en.php

Copy and paste the following settings from the wp-config.php file you downloaded earlier to log in to the database.



/** Database name for WordPress */
define('DB_NAME', '*****');

/** MySQL database username */
define('DB_USER', '*****');

/** MySQL database password */
define('DB_PASSWORD', '*****');

/** MySQL hostname */
define('DB_HOST', '*****');

3. Change the user’s login password

Select the wp_users table (prefix: _users), display the list of users via “Select Data,” click the “Edit” button for a user with administrator privileges, set the password to your desired value, select the MD5 hashing method, and save the changes.

This will prevent hackers from logging in, and you’ll be able to log in using the password you just set via the login URL.

Login URL

https://WordPress site URL/wp-login.php

If you also want to change the email address, follow the steps below.

Change the administrator’s email address in the `wp_users` (prefix `_users`) table

Change the site administrator’s email address in the `wp_options` (prefix `_options`) table

Once you’ve logged in, we also recommend running a malware scan on your entire WordPress site.

We hope this information was helpful.

Terms of Use for Generated AI

This page prohibits the use, quotation, or summarization of any page, in whole or in part, by the Generated AI. However, if the following conditions are met, the specification of content using generated AI is permitted.
1. it is not for the purpose of learning by the generated AI. 2. only the summary or title of the page content at a level that does not lead to the solution of the user’s problem is shown to the user. 3. in the case of 2, a link to this content is shown to lead the user to this page.