Skip to content
Popproxx brand logo in stylized cursive font.
An old padlock on a wooden table, surrounded by a ring of antique keys pointing toward it

Reset a WordPress Password Without Email

Jamin Giersbach
· Updated

The "Lost your password?" link on the WordPress login page is the easy way back in. It emails you a reset link. That only works if you can still open the email account on your profile, and if your site can send email. When either one fails, you're locked out of your own site.

You can still get in if you can reach the site's database or its command line. Both routes are in WordPress's own documentation, and neither needs email. This is how to do it without making things worse.

Try the reset email first

Go to your login page (usually yoursite.com/wp-login.php) and click Lost your password? Enter your username or email address, and WordPress emails a reset link to the address on your account. WordPress calls this the simplest and safest method, as long as you can open that email and your site's email is working (WordPress handbook).

Check your spam folder before you give up on it.

If someone else has an administrator account on the site, ask them next. An administrator can set a new password for you from Users > All Users: click your username, use the New Password section, and save (WordPress documentation). No database needed.

Back up the database

The phpMyAdmin method below edits your database by hand. WordPress's handbook calls changing passwords directly in the database high risk, and says to back up first, check the table prefix, and make sure you're changing the right user (WordPress handbook).

The quick backup in phpMyAdmin: select your WordPress database on the left, click the Export tab, leave Quick selected, click Go, and save the file to your computer (Backing Up Your Database). Keep it until you're back in and the site works.

If your host gives you SSH access with WP-CLI installed, the handbook recommends WP-CLI instead, as the safest and most straightforward method. Skip ahead to Use WP-CLI instead.

Reset it in phpMyAdmin

phpMyAdmin is a web tool for working with your site's database, and hosts often provide it (WordPress documentation). These steps follow WordPress's own instructions (handbook, WordPress.org).

1. Open your WordPress database

Log in to phpMyAdmin and click your site's database. If you see more than one, open wp-config.php, which sits in the root folder of your WordPress files. Its DB_NAME line is the name of the database your site uses (WordPress handbook).

2. Find the users table

Look for the table whose name ends in users. On many sites it's wp_users, but wp_ is only the default prefix. The $table_prefix line in the same wp-config.php file sets yours, so the table could just as well be example123_users (Editing wp-config.php).

3. Edit your row

Click Browse on the users table, find your username in the user_login column, and click Edit on that row. Check that it's your account before you change anything.

4. Set the new password with MD5

In the user_pass row you'll see a long string of letters and numbers: the stored hash of your old password. Delete it and type your new password in the value field. Passwords are case-sensitive, so type carefully. Then pick MD5 from the function dropdown on the same row, check that MD5 is showing, and click Go.

Don't skip the MD5 step. WordPress stores passwords as hashes, not as plain text, so a password typed into user_pass without a hashing function won't work (WordPress handbook).

And don't make the hash on an "MD5 generator" website, as some guides tell you to. Typing your new password into a stranger's site hands it to them. phpMyAdmin's dropdown does the same job without the password going anywhere but your own host.

Why MD5 is fine here. MD5 isn't how WordPress protects passwords. Since version 6.8, released in April 2025, WordPress hashes them with bcrypt (WordPress core team). The MD5 value is a temporary stand-in: it works for your first login, and after that login succeeds, WordPress replaces it with a stronger hash on its own (WordPress handbook). So log in straight away.

Log in and pick a new password

Log in with the password you just set. Then open your profile: it's under Users, or click your name at the top of the screen. In Account Management, generate a new password or type your own, and save. WordPress's strength indicator shows how strong it is (Your Profile screen).

The password you typed into phpMyAdmin was a quick fix. This is the one to keep, so make it long and unique, and store it in a password manager.

While you're on that screen:

  • Log Out Everywhere Else signs you out of your other devices, such as a phone or a public computer.
  • Fix the email address if it was one you can't open any more, so the reset link works next time.
  • Test your site's email if the reset message never arrived at an address you can open. Send yourself a message through your contact form. If that doesn't arrive either, your site isn't sending email, and its form messages may be going nowhere.

Use WP-CLI instead

WP-CLI is WordPress's command-line tool. If your host gives you SSH access and WP-CLI is installed, WordPress's handbook recommends it over phpMyAdmin: it resets the password without editing database tables by hand (WordPress handbook).

From the folder WordPress is installed in, run:

wp user update USERNAME --prompt=user_pass

Replace USERNAME with your login. The command also accepts your email address or user ID (wp user update). WP-CLI then asks you for the new password, so it doesn't end up in your shell history the way --user_pass=yourpassword on the command line would (WordPress handbook).

Don't know your username? wp user list shows every user on the site (WordPress documentation). Then log in and finish as above.

If you think someone broke in

Sometimes you're locked out because someone else changed your password. WordPress notes that attackers do hijack administrator accounts (FAQ My site was hacked). Getting your own login back is only the start:

  • Check for administrators you don't recognize. In Users > All Users, click the Administrator link above the list to see only administrators (Users screen). With WP-CLI, run wp user list --role=administrator (wp user list). New users you didn't create are one of the signs of a hack WordPress lists.
  • Change every password, not just yours: every user with access, your hosting control panel, FTP or SFTP, and the database.
  • Sign everyone out by replacing the secret keys in wp-config.php with a fresh set from WordPress's key generator. Anyone still logged in is forced out.
  • Change the passwords again once the site is clean, even if you changed them when you found the problem.

Those last three come from WordPress's own guide for hacked sites (FAQ My site was hacked), which also covers scanning and cleaning up.

Rather not touch the database?

I host and look after existing WordPress sites on LiteSpeed servers I run, case by case. Tell me about yours and I'll send a written quote for hosting and upkeep before anything changes. Content and design changes aren't included. A $500 deposit starts the quote. It's refundable until you accept, and credited to the work. Ask for a quote.

If you look after the site yourself, my posts on what it takes to look after a WordPress site and the 10 maintenance tasks to do every month cover the regular upkeep: updates, backups you can restore, and the checks that catch problems early.

Jamin Giersbach, who runs Popproxx
Written by

Jamin Giersbach

Jamin Giersbach is one of the three designers who started Popproxx in New York City in 2000. Early clients included WebMD, MSD Capital and Bookmans. In 2007 he took Popproxx to Oregon, and he has run it on his own ever since.

Read the full story →