SECURITY FINDING
Admin email found in a data breach
What it is
The email address tied to the WordPress admin account appears in known public data breaches. This does NOT mean the site itself has been hacked — it means that email/password combination is exposed elsewhere and could be reused against it.
How to fix it
Change the password anywhere it was reused, use a unique password for WordPress, and turn on two-factor authentication. Nothing on the site itself needs to change.
In depth
Your WordPress admin email address has been found in a public data breach somewhere on the internet, which means hackers have your email and possibly a password associated with it. This is serious because hackers often try using exposed email and password combinations on many different websites, including WordPress sites, so they might attempt to log into your site using these credentials. The good news is that this doesn't mean your WordPress site was actually hacked or compromised—it just means your admin email address is now known to be at risk. To fix this, you need to change your WordPress admin password to something completely new and unique that you've never used anywhere else, and check if you used that same password on any other accounts and change those too. After changing your password, you should enable two-factor authentication on your WordPress admin account, which adds an extra security step requiring a code from your phone whenever someone tries to log in, making it nearly impossible for hackers to access your site even if they have your password. You don't need to reinstall WordPress or make any technical changes to your website itself—just these account security steps will protect you.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.