Initial assessment without passwords Quote before intervention One accountable specialist from start to finish

Recover Control Safely

Recovering WordPress Access When the Administrator Email Was Changed

Recover WordPress after an administrator email change by securing the real mailbox, preserving user evidence and restoring one verified owner safely.

An unexpected administrator-email change redirects password resets and may show that an attacker already controlled WordPress or the owner’s mailbox. Changing the address back is necessary, but it does not remove active sessions, application passwords or persistence.

Secure external ownership first, then restore one verified WordPress owner.

Verify which email changed

WordPress has a site administration email and individual user email addresses. Record the old and current values, affected user IDs and change time from protected database or audit access.

Do not contact the unknown address or disclose the real owner publicly. Preserve the relevant user and option records before editing.

Check multisite network administrator and WooCommerce account contexts separately.

Secure the real owner mailbox

From a clean device, change the mailbox password, revoke sessions/app passwords, review recovery addresses and forwarding rules, and enable MFA.

Inspect recent security events for unauthorised access. An attacker who still controls email can repeat WordPress recovery or intercept hosting and DNS resets.

Use a dedicated organisational owner mailbox rather than a departing employee where possible.

Confirm hosting and DNS ownership

Verify control-panel users, SSH/SFTP keys, registrar/DNS/CDN users and billing contacts. Revoke unknown access and rotate credentials after preserving evidence.

Check whether the website points to the expected hosting account and database. A changed DNS record could present an attacker-controlled copy of the login page.

Do not enter replacement credentials through an unverified hostname.

Preserve WordPress account evidence

Snapshot the database and retain audit, access and security logs around the email change. Record who or what updated the profile and whether other users, roles or options changed.

Avoid exporting complete user tables or password hashes into support systems. Store originals under controlled incident access.

Time correlation can reveal whether a vulnerable endpoint or stolen session was used.

Restore a pre-verified owner

Use a trusted hosting/WP-CLI or scoped database method to restore the email for one known administrator and set a unique temporary password. Record the user ID and action.

Do not create a concealed permanent administrator. If an emergency account is required, name it transparently, limit its lifetime and remove it after owner recovery.

Revoke all WordPress sessions and unknown application passwords.

Check pending email-change workflows

WordPress or security plugins may store a pending admin email change that applies after confirmation. Inspect relevant options and plugin records so the unknown address does not return.

Clear only the confirmed malicious pending value. Do not delete unrelated transients or options broadly.

Test the legitimate change/confirmation flow on the recovered site.

Check security notifications

Search the trusted owner mailbox and mail-provider events for the original email-change notification, password resets and administrator alerts. Preserve message IDs and timestamps without forwarding reset links.

If notifications were redirected or suppressed, inspect SMTP settings, mailbox rules and recipient filters. An attacker may have changed both the account email and the site’s alert route.

Re-enable alerts only after sender and recipient ownership are verified.

Investigate how the change occurred

Review vulnerable/outdated plugins, administrator login logs, database access, injected PHP, must-use plugins and scheduled tasks. Compare core/plugins/themes with trusted packages.

Check whether the attacker changed SMTP or notification recipients to hide alerts. Review sibling sites sharing the same hosting credentials.

Replace untrusted code and close the entry point before reopening.

Verify all recovery routes

Confirm the site admin email, user email, hosting contact and primary mailbox all belong to approved owners. Request one test password reset and confirm its single-use link reaches the right mailbox.

Test administrator alerts, forms and WooCommerce email. Monitor future email, role and account changes.

Request urgent rescue when the unknown address reappears or the owner mailbox is also compromised. Share user IDs and redacted audit events—never reset tokens, credentials or user exports.

BEFORE YOU SEND THE REQUEST

Frequently asked questions.

Do you ask for passwords in the form?+

No. The public form never requests access. Secure credentials are requested only after the scope and quote are approved.

Who reviews the incident?+

The request goes to Jordi Ensenyat, founder of Code Barcelona and a WordPress specialist with more than 15 years of experience.

Is anything changed before the quote?+

No. Visible symptoms and scope are reviewed first. Intervention begins after approval and with a rollback path prepared.

Do you work internationally?+

Yes. WP Repair handles WordPress and WooCommerce incidents in English and Spanish through a remote service.

Assess my incident