WordPress Admin Email Changed? What It Means and What to Do
By Glenn Lyvers · Updated · 7 min read
If your WordPress admin email changed and you didn’t change it, assume someone has write access to your site or its database. Since WordPress 4.9, changing the site’s administration email through the dashboard requires clicking a confirmation link sent to the new address, and the old address gets notified — so a change that happened silently usually means the attacker went around that process entirely. Fix the address, then treat the site as compromised.
Why attackers change the admin email
The email address is the key to every recovery path WordPress has. Password reset links go to it. Update failure notices, new user notifications and security plugin alerts go to it. Whoever controls that address can reset the password on the account after you change it, and will quietly receive the warnings that would otherwise have told you something was wrong.
That makes it a persistence move, not just vandalism. An attacker who swaps the address can lose every other foothold — you delete their files, remove their user — and still walk back in with a “Lost your password?” click a week later.
I also see the address changed for a second, quieter reason: to hide the break-in. Security plugins, WordPress’s own recovery-mode emails and automatic update reports all go to the site email. Point that at a throwaway inbox and the owner simply stops hearing about anything — failed updates, new admin registrations, fatal errors caused by the malware itself. Weeks of silence from a site that used to email you regularly is worth noticing on its own.
There are two different emails — check both
WordPress keeps more than one address, and attackers target either:
| Address | Where it lives | What it controls |
|---|---|---|
| Site administration email | wp_options → admin_email (Settings → General) | Site-level notices, core update and recovery-mode emails |
| Pending site email change | wp_options → new_admin_email and adminhash | A change waiting for confirmation |
| Each user’s email | wp_users → user_email | Password resets for that account |
| Pending user email change | wp_usermeta → _new_email | A profile change waiting for confirmation |
The one that usually matters most is user_email on your administrator account, because that is where your password reset goes. Plenty of owners check Settings → General, see their own address and relax, while their user record points somewhere else.
How it gets changed without confirmation
The confirmation step only protects the dashboard form. It does nothing against:
- Direct database writes. SQL injection in a vulnerable plugin, stolen database credentials from an exposed
wp-config.phpor a leaked .env file, or phpMyAdmin access through a compromised hosting account. - Code running on the server. A web shell or backdoor can call
update_option()orwp_update_user()directly. So can a plugin vulnerability that lets unauthenticated visitors update options — the same class of bug behind the siteurl and home hijack. - A compromised administrator. Someone logged in as you can confirm a change if they also control the new inbox, which they do.
- A rogue admin account. The attacker creates their own administrator first, then edits yours at leisure. Check for hidden admin users before anything else.
How to check what’s actually set
With WP-CLI this takes seconds:
wp option get admin_email
wp option get new_admin_email
wp option get adminhash
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
Without shell access, in phpMyAdmin (adjust the wp_ prefix to yours):
SELECT option_name, option_value FROM wp_options
WHERE option_name IN ('admin_email','new_admin_email','adminhash');
SELECT ID, user_login, user_email, user_registered FROM wp_users;
SELECT user_id, meta_value FROM wp_usermeta WHERE meta_key = '_new_email';
A new_admin_email or adminhash value you didn’t request means someone started a change through the dashboard, which means they had an admin login. A different admin_email with no pending change points at a direct write. Note the address itself — it is evidence, and it sometimes matches the sender of phishing or spam coming from your site.
Fixing it, in the right order
- Look before you touch. Record the current values, the admin user list and recent file changes. If you may have notification obligations, preserve evidence first.
- Remove unknown administrators and reassign or delete their content.
- Reset the addresses.
wp option update admin_email you@yourdomain.com,wp option delete new_admin_email adminhash, andwp user update 1 --user_email=you@yourdomain.com(use your real user ID). The same can be done with anUPDATEin phpMyAdmin. - Change the passwords and kill sessions.
wp user session destroy --allsigns everyone out. Then change the salts inwp-config.phpso every existing login cookie stops working. - Rotate everything else. Hosting, database, FTP/SFTP, SMTP and API keys. If the attacker could read
wp-config.php, they have your database password; if you use an SMTP plugin, they may have your mail credentials too — see stolen SMTP credentials and the full credential rotation checklist.
If you are locked out because the reset emails go to the attacker, locked out of WordPress admin covers getting back in through the database or WP-CLI.
Rather hand it to me?
Every job is done by me personally, at a flat price per site, with written findings.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
Changing it back is not the fix
The email change is a symptom. Whatever made it — a backdoor, a vulnerable plugin, a stolen hosting password — is still there after you correct the address, and it can change it again tonight. This is the stage where most DIY cleanups stall: the visible damage is undone, the site looks normal, and the entry point is untouched.
Finish the job by finding how they got in. Check for PHP files that shouldn’t exist, malicious code in the database (my database malware guide has the queries), and plugins with known vulnerabilities. If that sounds like more than you want to take on, it is exactly the work my malware removal service covers — including the database, which is where this kind of change usually leaves its traces. You can also start with the free site scanner to see how much is visible from the outside.
Stopping it from happening again
Turn on two-factor authentication for every administrator, so a reset email alone is not enough to take the account. Keep the admin email on a mailbox you actually read, on a different provider from your hosting, so an attacker who owns the server does not also own your recovery inbox. Remove administrator rights from anyone who only writes posts. And have something — a plugin, a monitoring service, or a person — alert you when admin_email or an administrator’s user_email changes. It is a rare event on a healthy site, which makes it a very good alarm.
Common questions
Why did my WordPress admin email change by itself?
It didn't change by itself. WordPress does not alter the admin email on its own, and since version 4.9 a dashboard change requires confirmation from the new address. An unexpected change usually means someone wrote to the database directly, ran code on your server, or logged in as an administrator. Treat it as a sign of compromise until you know otherwise.
How do I change the WordPress admin email without confirmation?
Update the admin_email option directly, either with WP-CLI using wp option update admin_email followed by the address, or with an UPDATE query on the wp_options table in phpMyAdmin. Delete any leftover new_admin_email and adminhash options afterwards. For a user account, update user_email in wp_users or use wp user update with the user_email flag.
Is the site admin email the same as my user account email?
No. The site administration email in Settings, General is stored as admin_email in wp_options and receives site-level notices. Each user, including you, has a separate user_email in wp_users, and that is where password reset links for your account go. Attackers can change either one, so always check both.
Can a hacker reset my password if they changed my email?
Yes, and that is usually the point. If your user record points at their address, the Lost your password link sends a reset link to them. Correct the email, change the password, destroy all sessions, and change the salts in wp-config.php. Enabling two-factor authentication means a reset email alone is no longer enough to take over the account.
I fixed the email. Is my site clean now?
Probably not. Changing the email back undoes the symptom but not the cause. Whatever made the change, whether a backdoor, a vulnerable plugin or stolen hosting credentials, is still in place and can make the same change again. Check for unknown admin users, unexpected PHP files and malicious database entries before you consider the site clean.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.