Blog

I Found an Unknown Admin User in My WordPress: Have I Been Hacked?

Table of Contents

Introduction

You open Users inside your WordPress dashboard for some routine reason, and there it is: an account with the Administrator role that you never created. A strange name, an email you don't recognize, or even a name that mimics yours to stay under the radar.

The short answer is yes: if you find an administrator account you don't recognize, your WordPress has been compromised. It's not a system glitch or something that "generated itself." Let's look at what this actually means, how that user usually gets there, and what to do to fix it for good. If you want the full picture of what to do when your WordPress gets hacked, here's the general guide: My WordPress Site Was Hacked: What to Do Step by Step.

What it means to have an admin user you don't recognize

A user with the Administrator role has full control over your WordPress: they can install plugins, modify code, create more users, access the database through plugins, and basically do whatever they want with your site.

If you find one you didn't create, it means someone has gained administrative access to your site — and that user is very likely the backdoor they're using to get back in whenever they want, even if you change your own password at some point. With that level of access, it's also common for them to use your site to inject spam redirects, so if you spot a strange user it's worth checking both at the same time.

How attackers usually create this user

There are several common paths an attacker takes to create an admin user:

  • Brute force against the login: trying common or leaked passwords against your admin account until one works.
  • A vulnerable plugin or theme: many automated attacks exploit known flaws in outdated plugins that allow creating users without authentication.
  • Backdoors in code: a malicious file uploaded earlier that, when executed, silently creates an administrator account without leaving obvious traces in the usual logs.
  • XML-RPC abuse: an old WordPress feature that, if not properly protected, enables much faster brute-force attacks than the normal login form.

In most cases this isn't an attack targeted specifically at you, but a bot scanning thousands of sites looking for this exact vulnerability.

What to do immediately

  1. Don't just delete the user. It's almost everyone's first instinct, and it's a mistake: if the vulnerability that allowed it to be created is still open, the attacker simply creates another one the next time they get in.
  2. Change the passwords of every administrator account, not just yours, from a device you know is clean.
  3. Check for other suspicious users, including roles other than administrator — sometimes attackers create several lower-privilege users to stay less noticeable.
  4. Look for recently modified files or code, especially in plugins and themes, that could be the actual source of the backdoor.
  5. Check activity logs if your host or a security plugin keeps them, to try to pinpoint when and how the user was created.

Why just deleting the user isn't enough

Deleting the unknown admin user without investigating further treats the symptom without touching the cause. If the entry vector — a vulnerability, a weak password, a compromised plugin — is still active, it's only a matter of time before a new user shows up, or before the attacker uses an access method that no longer relies on any visible user in the dashboard.

Step by step for a complete fix

  1. Full diagnosis: identify how the user was created and what other files or code are affected.
  2. Remove the user and any associated backdoor in files, plugins, or the database.
  3. Close the specific vulnerability that allowed access (update plugins, strengthen passwords, review XML-RPC).
  4. Hardening: two-factor authentication, blocking repeated login attempts, periodic review of users.

When to get professional help

Finding an unknown admin user is a clear sign you need a real diagnosis, not just deleting the visible problem and hoping for the best. If you want someone to identify how they got in, remove the backdoor and close the door for good, here's how I approach hacked WordPress cleanup and security, with a free 24h diagnosis: Fix a hacked WordPress site

Conclusion

An admin user you don't recognize isn't a minor detail: it's proof that someone has, or had, full control over your site. Deleting it and moving on gives a false sense of security. The real fix means understanding how they got in, closing that door, and hardening access so they can't do it again.

© 2026 Fran Hurtado PortfolioPrivacy PolicyES