You cannot retrieve a WordPress password in readable form; you must reset it. Start at the login page by selecting Lost your password?, then enter the affected user’s username or account email. WordPress sends a reset link to that user’s address. Only move to administrator, WP-CLI, database, or FTP methods when the normal email route is unavailable.
Reset a WordPress password from the login page
- Open your site’s WordPress login page, usually
/wp-login.php. - Select Lost your password?.
- Enter the user’s username or the email address attached to that WordPress account.
- Submit the form and open the reset message sent to that address.
- Choose a new, unique password and sign in.
Check the spam or junk folder if the message does not appear. The address used for this reset belongs to the individual user; it may be different from the site-wide administration email used for general notifications.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
WordPress Multisite Administration | $34.38 | Buy on Amazon |
| 2 |
|
Mon Site WordPress – Volume 2 – Administration & Utilisation (French Edition) | $9.90 | Buy on Amazon |
| 3 |
|
WordPress 24-Hour Trainer | $3.95 | Buy on Amazon |
| 4 |
|
Teacher Record Book | $4.89 | Buy on Amazon |
If the reset email never arrives
- Confirm that you entered the correct username or account email and that you are checking that mailbox.
- Check spam, filtering rules, and quarantine folders.
- Consider whether the site can send email reliably; a delivery problem can prevent the link from arriving.
- Ask another site administrator or your hosting provider for help if you cannot access the mailbox or hosting controls.
If the site is displaying a critical PHP error rather than merely rejecting your password, that is a separate problem. WordPress Recovery Mode can pause a faulty plugin or theme for an administrator session after certain fatal errors; it is not a password-reset feature, and its recovery messages can also be blocked by mail delivery.
Choose an advanced recovery method only when you have the required access
| Method | Access required | Skill and risk | Cleanup |
|---|---|---|---|
| Login-page email | The user’s account email | Low; least risk | None |
| Another administrator or host | A trusted administrator account or hosting support | Low to moderate; verify the correct user | None |
| WP-CLI | Command-line access and administrator authority | Moderate; avoid exposing the new password | None |
| phpMyAdmin/MySQL | Database access and a verified backup | High; editing the wrong row or password format can lock you out | Undo only if an incorrect edit was made |
| FTP code or emergency script | FTP/server access | High; temporary code or an exposed script can let others change the password | Remove code and delete the script immediately |
Reset with WP-CLI
Current WordPress developer guidance treats WP-CLI as the safest straightforward technical fallback when a capable administrator has shell access. Run commands from the WordPress installation and replace USERNAME with the exact account identifier.
Recommended Free Tools
#1 Best Overall
Prompt for a new password
wp user update USERNAME --prompt=user_pass
This prompts for the replacement password instead of putting it directly in the command line, reducing exposure in shell history.
Generate a password
wp user reset-password USERNAME
Avoid printing or copying generated passwords unnecessarily: terminal history, logs, screenshots, and support sessions can retain plaintext credentials. Store the new password in a secure password manager or another protected location, then sign in and verify the account.
Use phpMyAdmin or MySQL only with a backup
Database recovery is a last resort for administrators who understand the hosting database tools. Back up the database first, identify the correct WordPress user table (its prefix may not be wp_), and verify the intended account before changing anything. WordPress documentation warns that direct database editing is risky, and entering a password as ordinary plain text in the password field will not work because WordPress expects its supported password format. Follow the current official instructions for your WordPress version rather than pasting an old SQL snippet.
Stop if you cannot verify the account
An incorrect table prefix, user row, or database can affect the wrong site or user. If you cannot confidently identify those values, ask your host or another administrator to perform the reset instead.
FTP and emergency PHP methods
Older official recovery guidance describes temporarily adding code to a theme file through FTP and using an emergency PHP script. These techniques can restore access when other routes are impossible, but they require precise file and account identification and are not the default recommendation.
- Use the current official procedure, not an unverified copy of an old snippet.
- Limit access to the temporary file or code while it exists.
- As soon as the password is reset, remove every temporary line and delete the emergency script.
- Clear any exposed credentials from support tickets, screenshots, logs, or shell history where possible.
A forgotten emergency script left on a public server can allow another person to change the password.
Rank #3
When WordPress still will not let you sign in
Check capitalization
WordPress usernames and passwords are case-sensitive. Re-enter the credentials exactly as set.
Clear the browser session
Clear WordPress-related cookies and cache, close the browser, and try again. A damaged login session can make a correct password appear to fail.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Check firewalls and security layers
A firewall or security plugin can interfere with login requests. If you control the site, review its blocking logs; otherwise ask the host or administrator to check them.
Rank #4
- Keep track of everything from attendance to test scores
- Spiral bound
- Measures 8-1/2" x 11"
Separate a password problem from a site outage
A critical-error page, blank page, or repeated server error requires site troubleshooting, not repeated password resets. Recovery Mode may help with certain fatal plugin or theme errors, but it does not recover credentials.
If you suspect the account was taken over
Treat the reset as the first step in a security incident. After regaining control, review administrator accounts, recent changes, plugins, themes, hosting access, and other login points. Remove unfamiliar users or code, update WordPress and extensions, rotate related credentials, and check that recovery email addresses are correct. Do not assume changing one password removes an attacker who still has another route into the site.
Quick Recap
Prevent the next lockout
- Use a strong, unique password for every WordPress account; never reuse a site password elsewhere.
- Keep the account email current and accessible.
- Save the password in a reputable password manager if that fits your security practice; a manager helps store a new password but cannot reveal a lost WordPress password.
- Keep at least one trusted administrator able to assist with account recovery.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches




