SECURITY FINDING
Hidden WordPress administrator account
What it is
There are more administrator accounts in the database than WordPress shows in the Users screen — an attacker created an admin and hid it from the list so they can log back in even after the site is cleaned. This is a strong sign of an active compromise.
How to fix it
Delete the hidden admin, then reset the passwords of every real admin plus the database and hosting account. Find the entry point (a vulnerable or nulled plugin) so it can't be recreated — the WordPress Plugin can find and report the hidden account for you.
In depth
Our security scan found an administrator account on your website that is not visible in your normal user list. This type of hidden account is typically created by hackers after they break into a site, allowing them to regain access even if you change your main passwords or remove other suspicious activity. A hidden admin account gives an attacker complete control over your website, your content, your visitors' data, and potentially your business reputation. You need to immediately delete this hidden account, then reset the passwords for all your real administrator accounts and your web hosting account. After that, update all your plugins and themes to the latest versions, as outdated software is usually how hackers get in initially. If you are not comfortable doing this yourself, contact your web hosting support team or hire a WordPress security specialist to remove the account and patch the vulnerability that allowed it to be created.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.