Unknown WordPress admin
A WordPress user you did not create is a break-in, not a glitch.
A new Administrator named something like “admin123,” a misspelled version of your name, or an author that is publishing posts you did not write. Delete them if you want — they will come back until the door they used is closed.
What this usually is
Unknown users mean someone had (or still has) the ability to write to the database. Common doors: stolen admin password, XML-RPC brute force, a vulnerable plugin, a leftover “admin” account from the original build, or a file that creates the user on every load. Deleting the row in wp_users without finding that file is a loop.
What you are probably seeing
- Administrator or Editor you did not create
- Author accounts publishing casino or pharma posts
- A user that returns after you delete it
- Last login or “registered” date that does not match any staff hire
- An “admin” account that is not the one you use
What not to do
- Do not only delete the user. Check whether a file or cron is recreating it.
- Do not email that user “who are you?” from the site. You are talking to the attacker.
- Do not reset only your password and leave every other administrator alone. Reset the ones you know, remove the ones you do not, then rotate secrets we can reach.
What we actually do
We dump the user list and creation dates, find how the account got there, remove leftover admins, and close the door (Phase B: passwords, salts we can reach, file editor off, login protection). That sits inside the published WordPress IR packages. If the same password is also the Microsoft 365 global admin, say that on the call — that is a bigger incident.
Published rates live on the WordPress incident-response packages page: Phase A from $2,500, Phase B from $2,000, combined from $4,200. Remote nationwide. Onsite in the Tri-Cities and Western North Carolina if you want someone in the room. If the WordPress site is the front door to a larger business compromise, start at emergency incident response instead.
Related WordPress problems
Same practice, same packages. Different search, different first paragraph.
Hacked WordPress
The site is compromised and you need it cleaned carefully, not rebuilt from a blank theme.
Spam links you did not add
Footer, sidebar, or post links appeared that nobody on your team added.
Gambling / casino / loan spam
Google shows casino, loan, or pill titles. Your pages look normal when you visit them logged in.
Safe Browsing / Search Console
Chrome or Search Console flagged the site. You need cleanup, then a recrawl — in that order.
Packages & pricing
Phase A, Phase B, and combined. Written report. Hosting can stay yours.
If this is your WordPress site
I deleted the user and they came back.
A file or a cron is recreating them. That is the incident. Deleting the row again will not finish the job.
Should I change my password before or after cleanup?
Change it now so the attacker has a harder time while we work — then we rotate remaining administrators and host-side secrets in Phase B. One password change is not the cleanup.
Can they still get in after I delete them?
Yes, if they still have a plugin backdoor, a file in mu-plugins, or FTP/SFTP. The user list is the symptom. The files are the cause.
Need the site cleaned without taking the store down?
Tri-Cities 423-888-0252 · Western NC 828-484-1257