Where WordPress stores your login information
Your WordPress admin username and password are not stored in one place you can look up — they live in your site's database, encrypted so no one (including WordPress staff) can read them. But you have several ways to recover them depending on what you still have access to.
If you remember your username but forgot your password, the login page has a reset link. If you do not remember your username either, you will need to check your email, your hosting control panel, or the database itself. The fastest route depends on what access you still have.
Key Takeaways
- The WordPress login page has a password reset link that works if you remember your username and can access the email address tied to your account.
- Your hosting control panel (cPanel, Plesk, or your host's dashboard) usually shows the database name and login, which you can use to look up your username in the wp_users table.
- The email address you used to set up WordPress is the fastest way to reset your password, because WordPress will send the reset link there.
- If you set up WordPress yourself, check your email inbox and spam folder for the original setup message from your host — it often contains your username.
- Changing your password in the WordPress dashboard is simpler than resetting it, so if you can log in at all, do that first.
Reset your password if you know your username
Go to your WordPress login page — usually yoursite.com/wp-login.php or yoursite.com/wp-admin. Look for the "Lost your password?" link below the login form. Click it and enter your username or the email address tied to your account.
WordPress will send a reset link to that email address. Check your inbox and spam folder. Click the link in the email, create a new password, and log in. This works as long as you still have access to the email address you used when you set up WordPress.
If you do not receive the email after five minutes, check your spam folder first. If it is not there, your email address may have been changed or deleted. Move to the next section.
Find your username in your hosting control panel
Log into your hosting account's control panel — usually cPanel, Plesk, or a custom dashboard from your host. Look for a section called "Databases", "MySQL", or "Database Manager". You should see a database name that matches your site, often something like "sitename_wp" or "wordpress_db".
Open the database manager (usually phpMyAdmin). Find the table called "wp_users" — it holds all your WordPress user accounts. Look at the "user_login" column to see your username. The "user_email" column shows the email address tied to that account.
Once you know your username and email, go back to the WordPress login page and use the password reset link. If you cannot find the database or do not have access to your hosting control panel, contact your hosting provider — they can tell you the database name or reset your password for you.
Check your email for the original setup message
When you first set up WordPress, your hosting provider or WordPress installation tool sent you an email with your login details. Search your email inbox for messages from your host, from WordPress, or from the email address associated with your domain. Look for subject lines like "WordPress Installation Complete", "Your WordPress Login", or "Account Information".
These emails often contain your username, a temporary password, and a link to your WordPress login page. If you find one, use the username to reset your password through the login page. Check your spam and promotions folders — these emails sometimes land there.
If you cannot find the original email and it has been more than a few months, it may have been deleted. Your hosting provider may still have a copy or a record of the username they assigned.
Use the WordPress database to change your password directly
If you have access to phpMyAdmin through your hosting control panel but cannot remember your email address or do not want to wait for a reset email, you can change your password directly in the database. This is more technical but works when other methods are blocked.
Open phpMyAdmin, find the wp_users table, and click on the row with your username. Find the "user_pass" field. WordPress stores passwords as hashes, not plain text, so you cannot just type a new one. Instead, use the MySQL function MD5() to hash your new password. In the user_pass field, enter: MD5('yournewpassword') — replace yournewpassword with what you want. Click Update.
Log into WordPress with your username and the new password you just created. Once you are in, go to your profile (click your name in the top right) and change your password through the WordPress dashboard — this is safer than editing the database again.
Contact your hosting provider if you cannot access the database
If you do not have access to your hosting control panel, cannot find your email, and do not remember your username, your hosting provider is your next step. They can verify you own the domain and reset your WordPress password or tell you your username.
Have your domain name and the email address or phone number tied to your hosting account ready. Some hosts can reset your password in minutes. Others may ask you to verify ownership through a code sent to your email or by answering security questions you set up when you created the account.
Change your password once you are logged in
Once you have reset your password and logged into WordPress, change it to something you will remember. Click your name in the top right corner of the WordPress dashboard, then click "Edit Profile". Scroll down to "Account Management" and click "Generate Password". WordPress will create a strong password for you, or you can type your own in the "New Password" field.
Click "Update Profile" at the bottom. Write down your new password somewhere safe — a password manager like Bitwarden or 1Password is better than a notebook. You now have a password you control and can use to log in anytime.
Frequently Asked Questions
Can I find my password if I forgot it and do not have access to my email?
No — WordPress passwords are encrypted and cannot be recovered. But you can reset it through your hosting control panel using phpMyAdmin, or contact your hosting provider to verify your identity and reset it for you. Both take 10 to 30 minutes.
What if I do not know my hosting provider or how to log into my control panel?
Check the domain registrar where you bought your domain name — they usually have a record of your hosting provider. You can also search your email for messages from your host. If you still cannot find it, search for your domain name plus "hosting" or look at your domain's nameservers in the registrar's dashboard.
Is it safe to change my password directly in the database?
It works, but it is riskier than using the WordPress password reset page because you have to edit the database directly. If you make a mistake, you could lock yourself out. Use the reset link first if you can. Only edit the database if the reset link does not work.
What if someone else set up my WordPress site for me?
Ask them for your username and password, or ask them to reset your password and send you the reset link. If you cannot reach them, use the password reset page with the email address tied to your account, or contact your hosting provider with proof that you own the domain.
Do I need to change my password if I found it?
Yes, especially if you found it written down or in an old email. Create a new, strong password through your WordPress profile. Use a password manager to store it so you do not have to write it down or remember it.