WordPress CMS admin password reset

Date posted: 2013-07-22
Last updated: 2026-10-03

Lost or forgotten your WordPress admin password? Reset it with a MySQL query, through functions.php over FTP, or with the lost password feature.

How do you reset your WordPress password? If you've lost or forgotten your WordPress admin password, you can easily reset it. Either use a MySQL statement to reset your WordPress admin password, or change it through your theme's functions.php file.

The quickest WordPress admin password reset is an UPDATE wp_users SET user_pass = MD5('...') query on your database; without database access, a temporary wp_set_password() call in functions.php does the trick. Either way, log on and set a new, strong password immediately, and remove any code you added.

Reset WordPress password through phpMyAdmin/MySQL

Use either phpMyAdmin or the mysql command line. The following MySQL statement resets your WordPress password to default. Don't forget to set a new password after logging on to your WordPress Dashboard, through your Profile settings:

UPDATE `wp_users` 
  SET `user_pass` = md5( "default" ) 
  WHERE `id` = 1;

Change wp_ to your WordPress MySQL table prefix. You can look up the WordPress user ID with the query:

SELECT * FROM wp_users;

If you have shell access and WP-CLI installed, wp user update 1 --user_pass='YourNewStrongPassword' sets a new password for user ID 1 directly, properly hashed.

Reset WordPress admin password through FTP

If you don't have direct access to your MySQL database, and you want to reset your WordPress admin password through FTP, follow these steps:

  1. log on to your website using FTP, and download your theme's functions.php file
  2. edit the functions.php file, and add on the second line (right below <?php): wp_set_password( 'default', 1 );. This sets the password to default for the user with ID "1".
  3. upload the file back to your website, to its original location
  4. log on to your WordPress website using this new password, change your password through your Profile settings, and remove the code from functions.php. Otherwise your password will be reset each time you try to log in.

Or you can do the downloading, editing and uploading of functions.php in one go, by editing a file through FTP. The article is in Dutch, but you can Google Translate the article or look at the screenshots. See the wp_set_password() reference for more information about the function.

The MySQL method stores the password as a plain MD5 hash, which is not secure! WordPress accepts it once and then rehashes it with its own, much stronger password hasher (originally the Portable PHP password hashing framework, bcrypt since WordPress 6.8). And default is anything but a strong password. That is exactly why you have to change the password as soon as possible after logging on.

Use a long, random password for your new WordPress password. Here is how to generate pseudorandom passwords with OpenSSL or create strong passwords in Windows.

Through the automatic emailer

If you know your username or the email address in your profile, you can use the "Lost your password?" feature of WordPress. If all else fails, use the emergency password reset script.

More password resets: Umbraco

Lost your Umbraco password? Read how to reset the Umbraco 8 admin password (in Dutch).

I write these posts in my spare time, based on real problems from my day job as a sysadmin. If this one saved you some debugging time, a small donation is much appreciated. Thanks! 🙏

Leave a Comment