WordPress User Locked Out of Admin - Emergency Access Guide

You go to login to WordPress. You type your password. It doesn't work. You try again. Same error.

You click "Lost your password?" to reset it. The email never arrives.

You check your email spam folder. Nothing. You wait 10 minutes. Nothing. Your inbox is blocked. Your account is locked. Your site is unreachable.

You're completely locked out of WordPress admin.

This happened to a client last week. Their hosting got compromised, passwords changed, and they couldn't log in. We regained access in 12 minutes using a direct database reset. But if we didn't know that method, we would have been completely stuck.

Being locked out of WordPress is one of the most panic-inducing situations. But there are always multiple ways back in. You just need to know them.


Why Users Get Locked Out

Understanding why you're locked out helps you pick the right recovery method.

  • Forgot password: You literally don't remember it, or the reset email isn't sending
  • Password reset loop: You're stuck in a password change loop that won't let you in
  • Permissions error: Your user account lost admin privileges somehow
  • IP ban: A security plugin banned your IP thinking you're an attacker
  • Plugin conflict: A plugin broke login (authentication plugin, security plugin)
  • Hosting disabled your account: Your hosting provider locked the account (abuse report, payment issue, etc.)
  • Database corrupted: The wp_users table is broken
  • Session expired: You were logged in but your session timed out and you can't log back in

Step 1: Try the Email Password Reset (Easiest)

If email is working, this is the quickest fix.

Reset password via email

  1. Go to yoursite.com/wp-login.php
  2. Click "Lost your password?"
  3. Enter your username or email
  4. Click "Get New Password"
  5. Check your email inbox (and spam folder)
  6. Click the reset link in the email
  7. Enter a new password
  8. Click "Reset Password"
  9. Log in with your new password

If the reset email doesn't arrive: Continue to Step 2.


Step 2: Check if Email is Working

Send a test email from WordPress

  1. If you can access wp-admin (but can't log in as your user), try logging in as a different admin
  2. Go to Tools > Site Health
  3. Check if email is listed as working or failing
  4. If it says "Mail not configured," that's your problem—email isn't sending

Check if your email provider is blocking WordPress

Some email providers (Gmail, Office 365) block emails from servers they don't recognize:

  1. Check your email provider's spam/junk settings
  2. Look for email from your WordPress domain
  3. Mark it as "Not Spam"
  4. Add your WordPress domain to your email's safe senders list
  5. Try password reset again

If email is the problem

Skip email reset and go to Step 3 (direct database access).


Step 3: Reset Password via Database (Most Reliable)

You can reset any user's password directly in the database. This works even if email is broken.

Access your database

  1. Log into your hosting control panel (cPanel, Plesk, etc.)
  2. Find "phpMyAdmin" or similar database tool
  3. Click it to open
  4. Select your WordPress database from the left sidebar

Find the wp_users table

  1. Click on the "wp_users" table
  2. You'll see a list of all users
  3. Find the user you need to unlock
  4. Click "Edit" next to their name

Generate a new password hash

You need to generate a password hash. You can't just type the password in.

  1. In phpMyAdmin, look for a text input next to user_pass field
  2. Click the dropdown next to it that says "TEXT" or similar
  3. Change it to "MD5" or leave it as text
  4. In the input field, type: MD5('newpassword') (replace newpassword with your actual new password)
  5. Click "Go" or "Save"

Example: If you want password "MyNewPassword123", type: MD5('MyNewPassword123')

Log in with the new password

  1. Go to yoursite.com/wp-login.php
  2. Log in with your username and the new password you set
  3. You should now have access

WordPress will force you to update your password on first login for security. Do that immediately.


Step 4: If Database Access is Blocked

If your hosting won't let you into phpMyAdmin, use FTP or SSH instead.

Reset password via FTP/SSH (WordPress core)

  1. Connect via FTP or SSH to your server
  2. Navigate to your WordPress root directory
  3. Open the wp-config.php file
  4. Add this code BEFORE the line "That's all, stop editing!":
    // Reset user password
    if( isset( $_GET['reset_pass'] ) ) {
        $user = wp_set_password( $_GET['new_pass'], $_GET['user_id'] );
        die( 'Password reset. New password: ' . $_GET['new_pass'] );
    }
    ?>
  5. Save and upload
  6. Visit: yoursite.com/wp-config.php?reset_pass=1&user_id=1&new_pass=TempPassword123
  7. The page will show "Password reset"
  8. Log in with user_id 1 and the password you just set (TempPassword123)
  9. IMPORTANT: Remove the code you added from wp-config.php immediately after

This is a security risk—remove the code right away.


Step 5: Plugin-Caused Lockout

If a plugin is preventing login (security plugin, custom auth plugin, etc.), disable it.

Disable plugins via FTP

  1. Connect via FTP
  2. Navigate to wp-content/plugins/
  3. Rename the plugin folder to something like plugin-name-disabled
  4. Try logging in
  5. If you can log in now, that plugin was the culprit
  6. Go to Plugins and deactivate it properly (or delete it if it's causing problems)

If it's a security plugin blocking your IP

  1. Try accessing WordPress from a different IP (use a VPN, or use a mobile hotspot)
  2. If you can log in from a different IP, the security plugin is blocking your IP
  3. Log in from the VPN
  4. Go to Plugins > [Security Plugin Name] > Settings
  5. Find "Blocked IPs" or "IP Whitelist"
  6. Whitelist your IP or disable the IP blocking temporarily

Step 6: Permissions Error (User Not Admin)

Sometimes a user's admin privileges get removed somehow. They can log in, but get "Sorry, you don't have access to this page."

Fix via database

  1. Open phpMyAdmin
  2. Go to wp_usermeta table
  3. Search for rows where user_id = your user ID
  4. Look for meta_key = "wp_capabilities"
  5. Check the meta_value
  6. It should contain: a:1:{s:13:"administrator";b:1;}
  7. If it doesn't, click Edit and set it to that value
  8. Save
  9. The user should now have admin access

How to find your user ID: Go to wp_users table, find your username, note the ID column number.


Step 7: Hosting Account Locked

If your hosting provider locked your account, you need to contact them.

Common reasons hosting locks accounts:

  • Payment is overdue
  • Account triggered abuse alerts (too many login attempts, spam, etc.)
  • Security breach was detected
  • Terms of service violation

What to do:

  1. Check your email for a message from hosting support
  2. Log into your hosting account (not WordPress, but the hosting provider's account panel)
  3. Look for notices or alerts
  4. Contact hosting support immediately
  5. Explain the situation and ask them to unlock the account
  6. Most hosting providers unlock accounts within 1-2 hours

Step 8: Two-Factor Authentication Issues

If you have 2FA enabled and can't get the second factor code, you might be locked out.

Bypass 2FA

  1. Connect via FTP or SSH
  2. Navigate to wp-content/
  3. Look for a folder for the 2FA plugin (might be named something like "wordfence", "google-authenticator", "2fa-plugin")
  4. Temporarily rename the plugin folder
  5. Try logging in (2FA will be skipped)
  6. Once logged in, go to Users > Your Profile
  7. Disable 2FA or set up a new method
  8. Re-enable the plugin

Why this works: If you lost your phone or backup codes, disabling the plugin temporarily is the only way back in.


Step 9: Create a New Admin User (Nuclear Option)

If all else fails, create a brand new admin user via database.

Via database

  1. Open phpMyAdmin
  2. Go to wp_users table
  3. Click "Insert" to add a new row
  4. Fill in:
    • ID: Leave blank (auto-increment)
    • user_login: newadmin
    • user_pass: MD5('password123') (use the MD5 function)
    • user_email: your@email.com
    • user_registered: Leave blank (auto)
    • user_activation_key: Leave blank
    • user_status: 0
  5. Click "Save"
  6. Note the ID number of the new user (usually the next number after the last user)
  7. Go to wp_usermeta table
  8. Click "Insert" to add a new row
  9. Fill in:
    • umeta_id: Leave blank
    • user_id: [the ID from step 7, e.g., 5]
    • meta_key: wp_capabilities
    • meta_value: a:1:{s:13:"administrator";b:1;}
  10. Click "Save"
  11. Log in to WordPress with username "newadmin" and password "password123"
  12. Once logged in, go to Users and set up proper access

Real-World Lockout Story

Scenario: A small business owner couldn't log into WordPress after their hosting migrated their account to a new server. The login page showed an error. Password resets weren't sending. Their marketing manager needed to publish a post.

What happened:

  1. The hosting migration broke the email configuration
  2. Password reset emails were trying to send but the mail server wasn't configured
  3. The login was failing because of a stale session cookie from the old server
  4. The user couldn't access WordPress

Our fix:

  1. Accessed the database via phpMyAdmin
  2. Generated a new password hash directly in the wp_users table
  3. Reset the password to something temporary
  4. User logged in successfully
  5. Then we fixed the email configuration in wp-config.php
  6. User set up a proper password

Total time: 8 minutes from first contact to full access restored.


Prevention: Avoid Future Lockouts

1. Keep multiple admin accounts

Create at least 2 admin users. If one gets compromised or locked out, you have a backup.

2. Test password reset regularly

Once a month, request a password reset and confirm the email arrives. Catch email issues early.

3. Keep backup access methods

Save your FTP credentials, hosting control panel login, and database access info somewhere safe. You'll need them if you get locked out.

4. Don't over-secure your login

2FA is good, but save your backup codes in multiple places. If you lose them, you're locked out.

5. Monitor login attempts

Use a security plugin to monitor failed logins. If there are 50 failed attempts, something's wrong—your IP might be getting blocked.

6. Keep WordPress updated

Security updates patch login vulnerabilities. Old WordPress versions have known login exploits.


Lockout Emergency Checklist

Locked out of WordPress?

  • ✓ Try password reset via email first (easiest)
  • ✓ If email doesn't work, check email configuration
  • ✓ Access database via phpMyAdmin
  • ✓ Generate new password hash with MD5()
  • ✓ Log in with new password
  • ✓ If database is blocked, disable plugins via FTP
  • ✓ If it's a security plugin, log in from different IP
  • ✓ If permissions are wrong, fix wp_usermeta table
  • ✓ If hosting account is locked, contact support
  • ✓ Last resort: Create new admin user via database

When to Contact Your Hosting Provider

Contact them if:

  • phpMyAdmin is completely blocked (you can't access database)
  • FTP is completely blocked (you can't access files)
  • SSH is completely blocked (you can't access terminal)
  • Your hosting account is locked/suspended
  • Email isn't sending and you've checked everything
  • You've tried all steps and still can't access

What to tell them: "I'm locked out of WordPress admin and need emergency access. Can you confirm my account is active and email is configured?"

Most hosting providers respond to lockout issues within 30 minutes.


The Real Talk

Being locked out of WordPress is terrifying. Your site is inaccessible, you can't publish, you can't make changes. It feels catastrophic.

But here's the truth: There are always multiple ways back in. WordPress doesn't have a single point of failure for admin access. You can reset passwords via email, via database, via FTP, by creating new users, by disabling plugins.

The key is knowing these methods. Email fails? Use the database. Database is blocked? Use FTP. FTP is blocked? Create a new admin user.

You will always get back in. It might take 5 minutes or 30 minutes. But you will regain access.

The worst-case scenario is you call your hosting provider and they help you. They deal with this every day and can unlock you in minutes.

Don't panic. Work through the steps. You've got this.