Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

FTP does not create a WordPress account by itself. It lets you place a temporary PHP snippet in the active theme; when WordPress loads a page, its user API creates the account. Use this recovery method only when you are authorized to administer the site, and remove the snippet immediately after access is restored.

Before you start

  • Confirm that you have the site owner’s permission to create an administrator.
  • Make a current backup of the file you will edit. Download the active theme’s functions.php so you can restore it if the site reports a PHP error.
  • Have FTP or, preferably, SFTP credentials and a strong, unique temporary password ready.

If the dashboard still works, use Users > Add New instead. FTP is a recovery and maintenance route, not the preferred routine for adding users.

Find the active theme file

  1. Connect to the correct WordPress installation with your FTP/SFTP client.
  2. Open wp-content/themes/.
  3. Identify the theme currently active on the site, then open its directory.
  4. Download that directory’s functions.php as a rollback copy.

Only the active theme’s file is normally loaded. Editing an inactive theme will appear to do nothing. A child theme, multisite setup, must-use plugin, caching layer or security plugin may require a site-specific placement instead.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Add a guarded account-creation snippet

Edit the active theme’s functions.php and place this code near the end, before a closing PHP tag if the file has one:

add_action('init', function () {
    $username = 'temporary_admin';
    $password = 'Use-a-long-unique-password-here';
    $email    = '[email protected]';

    if (username_exists($username) || email_exists($email)) {
        return;
    }

    $user_id = wp_create_user($username, $password, $email);
    if (!is_wp_error($user_id)) {
        $user = new WP_User($user_id);
        $user->set_role('administrator');
    }
});

What the code does

  • add_action('init', ...) runs the callback when WordPress initializes.
  • username_exists() and email_exists() prevent a duplicate account from being created on later page loads.
  • wp_create_user() creates the user with WordPress’s normal password handling and returns a user ID or a WP_Error.
  • set_role('administrator') assigns the built-in full-site administrator role. That role can manage users, content, plugins and themes.

Replace all three example values. Do not reuse the displayed password, and do not include an account name or address that belongs to someone else.

When to use wp_insert_user()

wp_create_user() is the concise API. Use wp_insert_user() when you need to provide an explicit role or additional user fields in one data array. It returns a new user ID or a WP_Error; both APIs are preferable to manually editing password hashes or capability rows in the database.

Upload, trigger, and sign in

  1. Save the edited file and upload it back to the same active-theme directory.
  2. Request one ordinary front-end URL for that WordPress installation. This loads the file and lets the init callback run.
  3. Do not repeatedly refresh while the snippet remains online.
  4. Open /wp-admin/ or the site’s normal login URL and sign in with the temporary credentials.
  5. Go to Users and verify that the account exists and has the Administrator role.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Remove the recovery code immediately

  1. Delete the entire temporary snippet from functions.php.
  2. Upload the cleaned file.
  3. Create a permanent, named administrator account if needed.
  4. Change the temporary account’s password or delete it after confirming the permanent account works.

Leaving the snippet online exposes a hard-coded credential and keeps account-creation logic on every page load. If the recovery began because of a suspected compromise, review existing administrator accounts and investigate other unauthorized changes after access is secured.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the account is not created

  • Wrong file: confirm that the directory belongs to the active theme, not an inactive theme.
  • Wrong installation: check that the FTP path contains the intended site’s wp-admin, wp-content and wp-includes directories.
  • File not loaded: upload the file again and request a normal page after the upload.
  • Existing username or email: the guard intentionally stops when either already exists; choose a different temporary username and email, or inspect the existing account.
  • PHP error or blank site: immediately replace the edited file with the downloaded backup, then investigate syntax and hosting logs before trying again.
  • Special installation: multisite, a child theme, a must-use plugin, page caching or a security plugin can change execution behavior. Follow that installation’s specific recovery procedure rather than repeatedly refreshing this snippet.

Choosing a recovery method

Method Access required Code or database handling Rollback and security considerations
WordPress dashboard Working administrator session No code; use Users > Add New Lowest risk and easiest cleanup
FTP/SFTP snippet Site file access Temporary PHP in the active theme Restore the file on error and remove the snippet immediately
Hosting file manager Hosting control-panel file access Same PHP approach as FTP Use a downloaded backup and verify the correct installation
SSH or WP-CLI Shell access and an installed WP-CLI environment Command-line user creation Useful for operators who already manage the server; command and permissions are site-specific
Direct database editing Database credentials or administration tool Manual password and capability data Highest error risk; avoid unless you have a tested backup and understand the site’s table prefix

Security checks after recovery

  • Use a unique, long password for every administrator.
  • Remove the temporary code and account as soon as the permanent login is confirmed.
  • Review the administrator list for unfamiliar accounts.
  • Check recently modified theme, plugin and core files if unauthorized access is suspected.
  • Keep a backup before making further repairs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.