Unauthorized Administrators in WordPress
An administrator you never created is the clearest indication that access was successfully gained. The account itself is rarely the actual problem, since it can be created again at any time as long as the entry point remains open.
That is why the first question is how the account came about.
WordPress expert from Schleswig
★★★★★ 5,0 on Google
- Response within 4 hours
- Site clean again within 6 hours – otherwise you only pay half
- €280 fixed price plus VAT
- Money-back guarantee
Report an emergency
I will get back to you within 4 hours.
How to Recognize Unauthorized Accounts
The accounts are usually named in such a way that, at a glance, they look technical.
Technical-Sounding Names
Names such as wpsvc, wp-admin-service or backup-user. The associated email addresses point to domains that do not exist.
Created Within a Narrow Time Window
Multiple accounts are created within a few minutes. The date is the best starting point for analyzing the logs.
Accounts Without Login Activity
A backup access account that is deliberately not used so it does not attract attention. It only becomes active once the first backdoor has been removed.
Hidden Accounts
Some accounts are hidden from the user overview and are only visible in the database. Looking only in the backend is therefore not enough.
The Right Approach
Do Not Delete Anything Immediately
As long as the accounts exist, the logs can be used to reconstruct when and by what route they were created. Once deleted, this trace is missing.
Check the Database Instead of the Backend
The user table is read directly so that hidden accounts are also visible. The same applies to the assignment of permissions.
Close the entry point
Only once it has been established how the accounts were created are they removed and the vulnerability closed. Subsequently, all passwords are renewed.
Transparent costs
Malware scan
plus VAT · one-time
- Complete inspection of files, database and server configuration
- Analysis of access logs
- Written report with all findings
- Strong IT compliance image
If you commission the cleanup afterwards, the 50 € will be fully credited.
Most frequently chosen
Cleanup
plus VAT · fixed price, scan included
- Everything from the scan
- Complete removal of malicious code
- Restoration of normal operation
- Closing the entry point, changing all access credentials
- Security measures
- Report for the insurance company (+200€)
✓ Money-back guaranteeIf I can't clean the site, you pay nothing.
Ongoing support
per month, plus VAT.
- Updates for core, plugins and themes – checked, not installed blindly
- regular malware check
- Ongoing comparison with newly reported vulnerabilities
- Malware removal included free of charge during the support period
The complete fine print:
- All prices are plus 19 % VAT.
- Orders processed on Saturdays, Sundays or public holidays cost an additional one-time 100 € weekend surcharge.
- Response and recovery times apply Monday to Friday from 8 a.m. to 8 p.m. Outside these hours, I will respond as quickly as I can, but without a guarantee.
- The time starts when I have received all the necessary access credentials – not from your first message.
- I discuss special cases such as multiple sites in one installation, WooCommerce with ongoing orders or multisite with you beforehand and tell you the price before I start.
Frequently asked questions
Can't I just delete the accounts?
You can, and in an acute situation that is better than nothing. But it does not change the cause: as long as the entry point remains open, new accounts will be created within hours. In addition, you will lose the traces needed to analyze the cause.
Where do such accounts come from?
Usually through a vulnerability in an outdated plugin or in WordPress itself, and less often through compromised credentials. The access logs reveal which route was involved in the individual case.
Do I have to report it?
If an unauthorized administrator account existed, access to all data stored on the website was fundamentally possible. Whether this gives rise to a reporting obligation under Article 33 GDPR is a legal question. My findings provide the technical basis for the assessment.
An unauthorized administrator means full access to your data
A call costs you nothing and takes five minutes. If it turns out to be a different problem, I will tell you that too.
Available Monday to Friday from 8 a.m. to 8 p.m. · Related topics: WordPress hacked – what to do now · No longer able to access WordPress · Secure WordPress · Remove WordPress virus
Prefer a quick chat
The longer an infection remains undetected, the greater the damage usually becomes. Attackers create additional access points, manipulated pages may be marked as unsafe by Google, and domains can end up on spam blacklists. Even after the technical cleanup, it can take time for such warnings to disappear. That's why it's worth checking early whether an infection is actually present. In a short phone call, it is usually possible to assess what has happened and which next steps make sense.
- Malware scan with written findings50 €
- Fixed-price cleanup, scan included280 €
- Ongoing support, monthlyfrom 65 €
All prices plus VAT · Response within 4 hours, Monday to Friday from 8 a.m. to 8 p.m.