WordPress Hacker Added Admin Account β Can't Delete It: The Backdoor Problem
You're auditing your WordPress Users list and notice an admin account you don't recognize. "help" or "wp_admin" or something random. You click Delete. It says "User deleted." You refresh the page. The account is still there. Or it keeps coming back hours later. This isn't a WordPress bug. You've been compromised with a persistent backdoor.
What's Actually Happening
When you can't delete a hacker's admin account, it means one of two things:
1. A Backdoor Plugin Is Recreating It
The hacker didn't just add an admin account. They installed malicious code (usually hidden in a plugin or as a wp-cron task) that continuously recreates the account if it's deleted. The two most common backdoors discovered by Sucuri researchers in 2025:
DebugMaster Pro (Hidden Plugin)
- Disguises itself as a legitimate debugging tool
- Creates a hidden admin account (usually named "help")
- Removes itself from the WordPress plugin list (you won't see it in Plugins)
- If you delete the admin account, it recreates it on the next execution
- Hides the account from user queries so it doesn't always show in the Users list
wp-user.php (Root-Level Backdoor Script)
- Placed in the WordPress root or a hidden folder
- Sole job: ensure a specific admin account (usually "help") always exists
- If you change the password, it resets it
- If you delete the account, it recreates it
- Runs automatically through wp-cron or server cron
2. The Delete Button Doesn't Actually Work
The account delete fails silently. You see "User deleted," but the database transaction never completes. This happens when:
- Malicious code in functions.php hooks into the user deletion process and blocks it
- A plugin (or backdoor disguised as a plugin) filters the delete request and kills it
- Database file permissions are locked (your host won't let you modify wp_users directly)
- A mu-plugin (must-use plugin) prevents deletions
How to Identify the Backdoor
Step 1: Check Your Plugins Folder
Open your FTP client or file manager and navigate to /wp-content/plugins/
Look for:
- DebugMaster (any variant: DebugMaster Pro, debug-master, etc.)
- Any plugin you don't recognize or don't remember installing
- Plugins with generic names: wp-admin, wp-backup, wp-security, wp-tools
- Folders with hashed names or numbers (e.g., sg8f7k, wp_8a2d1, etc.)
- Very new plugins (check the modified date) you didn't install
If you find it: Don't delete it from the WordPress admin (the backdoor might block it). Instead, use FTP to delete the entire folder. Then check step 2.
Step 2: Check Must-Use Plugins
Navigate to /wp-content/mu-plugins/
Files here load automatically before regular plugins. Look for:
- Any .php file you don't recognize
- Obfuscated code (lots of base64, hex encoding, or eval() statements)
- Files with random names (wp_user.php, db_functions.php, security.php, etc.)
Delete any suspicious files via FTP.
Step 3: Check Your WordPress Root
Navigate to your WordPress root directory (/public_html/ or wherever WordPress is installed).
Look for:
- wp-user.php (most common backdoor name)
- wp-admin.php
- db.php or database.php
- Any .php file in the root with a suspicious name or recent modification date
Do NOT delete wp-config.php (that's your real config file). Only delete suspicious files you didn't create.
Step 4: Check functions.php
Navigate to /wp-content/themes/your-theme/functions.php
Open it in a text editor. Look for:
- Code that creates users with specific usernames (search for
wp_create_userorwp_insert_user) - Heavily obfuscated code (base64_decode, eval, create_function)
- Code you didn't write or don't recognize
- Inline functions that handle HTTP requests (
$_GET,$_POST)
Delete malicious code, but don't accidentally delete legitimate functions.
Remove the Hacker's Admin Account (Permanently)
Option 1: Delete Directly From the Database (Most Reliable)
If you can't delete the account from WordPress admin, go straight to the database.
Step 1: Access phpMyAdmin
- Log into cPanel β Databases β phpMyAdmin
- Or ask your hosting provider for phpMyAdmin access
Step 2: Find the wp_users Table
- Click on your database name (left sidebar)
- Scroll down and find the table
wp_users - Click on it to open it
Step 3: Identify the Hacker's Account
Look for accounts with:
- Usernames like: "help," "admin2," "wp_admin," "test_admin," "adm1nlxg1n," or anything you don't recognize
- Very recent
user_registereddates that don't match when you created accounts - Suspicious emails or no email address at all
Step 4: Delete the Row
- Find the malicious account row
- Click the checkbox to select it
- At the bottom, find the Delete button and click it
- Confirm the deletion
Step 5: Check wp_usermeta for Leftover Capabilities
The account is gone, but its meta data might still exist in wp_usermeta
- Click on the
wp_usermetatable - Look for rows where
user_idmatches the deleted account's ID - Delete those rows too
Option 2: Use a SQL Query (Fast for Multiple Backdoor Accounts)
If there are multiple hidden accounts, use the phpMyAdmin SQL editor.
In phpMyAdmin:
- Click the SQL tab at the top
- Paste this query (replace "help" with the actual username):
DELETE FROM wp_users WHERE user_login = 'help';
Click Go to execute.
Then remove leftover meta data:
DELETE FROM wp_usermeta WHERE user_id = (SELECT ID FROM wp_users WHERE user_login = 'help');
For multiple accounts at once:
DELETE FROM wp_users WHERE user_login IN ('help', 'admin2', 'test_admin');
Complete Cleanup Checklist
| Action | How to Check | Where to Clean |
|---|---|---|
| Remove backdoor plugins | FTP: /wp-content/plugins/ for suspicious folders | Delete entire plugin folders via FTP |
| Remove mu-plugins | FTP: /wp-content/mu-plugins/ for any files | Delete suspicious .php files via FTP |
| Remove backdoor scripts | FTP: WordPress root for wp-user.php, etc. | Delete via FTP, not WordPress admin |
| Delete admin account | phpMyAdmin: wp_users table | Delete row, then check wp_usermeta |
| Reset all passwords | WordPress admin β Users β Edit | Change WordPress admin password |
| Reset FTP/SSH credentials | Hosting control panel (cPanel, etc.) | Reset in hosting account settings |
| Reset database password | Update wp-config.php with new credentials | Hosting control panel β Databases |
| Update all plugins/themes | WordPress admin β Dashboard | Install all available updates immediately |
What If the Account Keeps Coming Back?
You deleted the account and the backdoor file, but the account reappeared the next day. This means:
1. You didn't delete the backdoor code β it's still running somewhere. Check:
- All active theme and child theme functions.php files
- Any theme-specific PHP files (404.php, index.php, etc.) that might have code injected
- Hidden plugins in /wp-content/ with folder names you didn't recognize
2. There's a second backdoor file you missed β Search your entire WordPress installation for files modified on the hack date. Use your hosting control panel or FTP client's search feature.
3. The hacker has hosting-level access β They added the backdoor through your FTP credentials, not WordPress. In this case, you need to:
- Change your FTP/SSH password immediately
- Scan your entire server (ask your host to scan, or use Wordfence)
- Check cron jobs (cPanel β Cron Jobs) for suspicious tasks running at odd times
Temporary Fix: Disable User Creation in wp-config.php
While you're hunting for the backdoor, prevent it from creating new accounts:
// Add this to wp-config.php (TEMPORARY - remove after cleanup)
define('DISALLOW_USER_CREATION', true);
Remove this line after you've fully cleaned your site. It's only a band-aid.
When to Call a Professional
If after following these steps:
- The account keeps coming back
- You can't find the backdoor code
- Your site keeps getting re-hacked days later
- You're not confident editing files via FTP or phpMyAdmin
Contact a professional WordPress security company:
- Sucuri (sucuri.net) β specializes in WordPress malware removal
- Wordfence (wordfence.com) β has a security team for cleanup
- GOTMLS (gotmls.net) β affordable WordPress malware removal
A full cleanup usually costs $200β500 and takes 24β48 hours. It's worth it if your site is mission-critical.
How to Prevent This Next Time
1. Keep WordPress, plugins, and themes updated β Most hacks exploit known vulnerabilities. Outdated software is the #1 attack vector.
2. Use strong, unique passwords β For WordPress admin, FTP, hosting control panel, and database. Use a password manager.
3. Limit login attempts β Install a plugin like Wordfence or Jetpack to block brute-force attacks on /wp-login.php
4. Audit your plugins monthly β Uninstall plugins you don't use. Hackers often compromise old, unmaintained plugins.
5. Set file permissions correctly β wp-content and wp-config.php should not be world-writable (644 or 644/755)
6. Use a Web Application Firewall (WAF) β Cloudflare, Sucuri, or your host's WAF can block common attack patterns before they hit your site.
7. Scan regularly β Use Wordfence, WP Security Auditor, or request your host scan your site monthly.
The Real Talk
A hacker admin account that won't delete is the sign of a serious compromise. It means the hacker didn't just break inβthey installed a persistence mechanism to stay in, even after you think you've kicked them out.
If you follow the steps above (delete the backdoor file, delete the account from the database, reset all passwords), you should regain control. But if it keeps coming back, the hacker likely has deeper access than you think. That's when professional help makes sense.
The good news: WordPress sites can be fully recovered, and with better security practices, they rarely get hacked the same way twice.
Last updated: October 2026. Real data: Sucuri security research (DebugMaster Pro, wp-user.php backdoors), WordPress.org support forums, GOTMLS malware analysis, WordPress Core security documentation.
