WordPress Admin Email Changed? What It Means and What to Do

By · Updated · 7 min read

If your WordPress admin email changed and you didn’t change it, assume someone has write access to your site or its database. Since WordPress 4.9, changing the site’s administration email through the dashboard requires clicking a confirmation link sent to the new address, and the old address gets notified — so a change that happened silently usually means the attacker went around that process entirely. Fix the address, then treat the site as compromised.

Why attackers change the admin email

The email address is the key to every recovery path WordPress has. Password reset links go to it. Update failure notices, new user notifications and security plugin alerts go to it. Whoever controls that address can reset the password on the account after you change it, and will quietly receive the warnings that would otherwise have told you something was wrong.

That makes it a persistence move, not just vandalism. An attacker who swaps the address can lose every other foothold — you delete their files, remove their user — and still walk back in with a “Lost your password?” click a week later.

I also see the address changed for a second, quieter reason: to hide the break-in. Security plugins, WordPress’s own recovery-mode emails and automatic update reports all go to the site email. Point that at a throwaway inbox and the owner simply stops hearing about anything — failed updates, new admin registrations, fatal errors caused by the malware itself. Weeks of silence from a site that used to email you regularly is worth noticing on its own.

There are two different emails — check both

WordPress keeps more than one address, and attackers target either:

AddressWhere it livesWhat it controls
Site administration emailwp_options → admin_email (Settings → General)Site-level notices, core update and recovery-mode emails
Pending site email changewp_options → new_admin_email and adminhashA change waiting for confirmation
Each user’s emailwp_users → user_emailPassword resets for that account
Pending user email changewp_usermeta → _new_emailA profile change waiting for confirmation

The one that usually matters most is user_email on your administrator account, because that is where your password reset goes. Plenty of owners check Settings → General, see their own address and relax, while their user record points somewhere else.

How it gets changed without confirmation

The confirmation step only protects the dashboard form. It does nothing against:

  • Direct database writes. SQL injection in a vulnerable plugin, stolen database credentials from an exposed wp-config.php or a leaked .env file, or phpMyAdmin access through a compromised hosting account.
  • Code running on the server. A web shell or backdoor can call update_option() or wp_update_user() directly. So can a plugin vulnerability that lets unauthenticated visitors update options — the same class of bug behind the siteurl and home hijack.
  • A compromised administrator. Someone logged in as you can confirm a change if they also control the new inbox, which they do.
  • A rogue admin account. The attacker creates their own administrator first, then edits yours at leisure. Check for hidden admin users before anything else.

How to check what’s actually set

With WP-CLI this takes seconds:

wp option get admin_email
wp option get new_admin_email
wp option get adminhash
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Without shell access, in phpMyAdmin (adjust the wp_ prefix to yours):

SELECT option_name, option_value FROM wp_options
 WHERE option_name IN ('admin_email','new_admin_email','adminhash');
SELECT ID, user_login, user_email, user_registered FROM wp_users;
SELECT user_id, meta_value FROM wp_usermeta WHERE meta_key = '_new_email';

A new_admin_email or adminhash value you didn’t request means someone started a change through the dashboard, which means they had an admin login. A different admin_email with no pending change points at a direct write. Note the address itself — it is evidence, and it sometimes matches the sender of phishing or spam coming from your site.

Fixing it, in the right order

  1. Look before you touch. Record the current values, the admin user list and recent file changes. If you may have notification obligations, preserve evidence first.
  2. Remove unknown administrators and reassign or delete their content.
  3. Reset the addresses. wp option update admin_email you@yourdomain.com, wp option delete new_admin_email adminhash, and wp user update 1 --user_email=you@yourdomain.com (use your real user ID). The same can be done with an UPDATE in phpMyAdmin.
  4. Change the passwords and kill sessions. wp user session destroy --all signs everyone out. Then change the salts in wp-config.php so every existing login cookie stops working.
  5. Rotate everything else. Hosting, database, FTP/SFTP, SMTP and API keys. If the attacker could read wp-config.php, they have your database password; if you use an SMTP plugin, they may have your mail credentials too — see stolen SMTP credentials and the full credential rotation checklist.

If you are locked out because the reset emails go to the attacker, locked out of WordPress admin covers getting back in through the database or WP-CLI.

Changing it back is not the fix

The email change is a symptom. Whatever made it — a backdoor, a vulnerable plugin, a stolen hosting password — is still there after you correct the address, and it can change it again tonight. This is the stage where most DIY cleanups stall: the visible damage is undone, the site looks normal, and the entry point is untouched.

Finish the job by finding how they got in. Check for PHP files that shouldn’t exist, malicious code in the database (my database malware guide has the queries), and plugins with known vulnerabilities. If that sounds like more than you want to take on, it is exactly the work my malware removal service covers — including the database, which is where this kind of change usually leaves its traces. You can also start with the free site scanner to see how much is visible from the outside.

Stopping it from happening again

Turn on two-factor authentication for every administrator, so a reset email alone is not enough to take the account. Keep the admin email on a mailbox you actually read, on a different provider from your hosting, so an attacker who owns the server does not also own your recovery inbox. Remove administrator rights from anyone who only writes posts. And have something — a plugin, a monitoring service, or a person — alert you when admin_email or an administrator’s user_email changes. It is a rare event on a healthy site, which makes it a very good alarm.

Common questions

Why did my WordPress admin email change by itself?

It didn't change by itself. WordPress does not alter the admin email on its own, and since version 4.9 a dashboard change requires confirmation from the new address. An unexpected change usually means someone wrote to the database directly, ran code on your server, or logged in as an administrator. Treat it as a sign of compromise until you know otherwise.

How do I change the WordPress admin email without confirmation?

Update the admin_email option directly, either with WP-CLI using wp option update admin_email followed by the address, or with an UPDATE query on the wp_options table in phpMyAdmin. Delete any leftover new_admin_email and adminhash options afterwards. For a user account, update user_email in wp_users or use wp user update with the user_email flag.

Is the site admin email the same as my user account email?

No. The site administration email in Settings, General is stored as admin_email in wp_options and receives site-level notices. Each user, including you, has a separate user_email in wp_users, and that is where password reset links for your account go. Attackers can change either one, so always check both.

Can a hacker reset my password if they changed my email?

Yes, and that is usually the point. If your user record points at their address, the Lost your password link sends a reset link to them. Correct the email, change the password, destroy all sessions, and change the salts in wp-config.php. Enabling two-factor authentication means a reset email alone is no longer enough to take over the account.

I fixed the email. Is my site clean now?

Probably not. Changing the email back undoes the symptom but not the cause. Whatever made the change, whether a backdoor, a vulnerable plugin or stolen hosting credentials, is still in place and can make the same change again. Check for unknown admin users, unexpected PHP files and malicious database entries before you consider the site clean.