In WordPress, there is more than one way to reset your password. (Normally, the easiest way to reset it is through the “Lost your password?” link on the main login page for your blog or website.)
However, there are certain times (especially if your email isn’t working correctly) that you may have to take different steps to reset your password.
Here’s a list of different ways to reset a password. The method that you use depends on the type of access that you still have to your website.
To Change Your Password
To change your password in current versions:
- In the Administration Screen, menu, go to Users > All Users.
- Click on your username in the list to edit it.
- In the Edit User screen, scroll down to the New Password section and click the Generate Password button.
- If you want to change the automatically generated password, you can overwrite it by typing a new password in the box provided. The strength box will show you how good (strong) your password is.
- Click the Update User button.
Your new password becomes active immediately.
Through the automatic emailer
If you know your username or the email account in your profile, you can use the “lost password” feature of WordPress.
- Go to your WordPress Login page (something like http://yoursite.com/wordpress/wp-login.php)
- Click on the “Lost your password?” link
- You will be taken to a page to enter some details. Enter your username or the email address on file for that account.
- Wait happily as your new password is emailed to you.
- Once you get your new password, login to your profile page and change this password to something you can remember.
Through MySQL Command Line
- Get an MD5 hash of your password.
- Visit md5 Hash Generator, or…
- Create a key with Python, or…
- On Unix/Linux:
- Create a file called wp.txt, containing nothing but the new password.
- tr -d ‘\r\n’ < wp.txt | md5sum | tr -d ‘ -‘
- rm wp.txt
- On Mac OS X:
- Create a file called wp.txt, containing nothing but the new password. Then enter either of the lines below
- md5 -q ./wp.txt; rm ./wp.txt (If you want the MD5 hash printed out.)
- md5 -q ./wp.txt | pbcopy; rm ./wp.txt (If you want the MD5 hash copied to the clipboard.)
- “mysql -u root -p” (log in to MySQL)
- enter your mysql password
- “use (name-of-database)” (select WordPress database)
- “show tables;” (you’re looking for a table name with “users” at the end)
- “SELECT ID, user_login, user_pass FROM (name-of-table-you-found);” (this gives you an idea of what’s going on inside)
- “UPDATE (name-of-table-you-found) SET user_pass=”(MD5-string-you-made)” WHERE ID = (id#-of-account-you-are-reseting-password-for);” (actually changes the password)
- “SELECT ID, user_login, user_pass FROM (name-of-table-you-found);” (confirm that it was changed)
- (type Control-D to exit mysql client)
Note: if you have a recent version of MySQL (version 5.x?) you can have MySQL compute the MD5 hash for you.
- Skip step# 1 above.
- Do the following for step# 7 instead.
- “UPDATE (name-of-table-you-found) SET user_pass = MD5(‘(new-password)’) WHERE ID = (id#-of-account-you-are-reseting-password-for);” (actually changes the password)
Note that even if the passwords are salted, meaning they look like $P$BLDJMdyBwegaCLE0GeDiGtC/mqXLzB0, you can still replace the password with an MD5 hash, and WordPress will let you log in.
This article is for those who have phpMyAdmin access to their database. Note: use phpMyAdmin at your own risk. If you doubt your ability to use it, seek further advice. WordPress is not responsible for loss of data.
- Begin by logging into phpMyAdmin and clicking databases.
- A list of databases will appear. Click on your WordPress database.
- All the tables in your database will appear. If not, click Structure.
- Look for wp_users in the Table column.
- Click on the icon for browse.
- Locate your username under user_login
- Click edit (may look like a pencil icon in some versions of phpMyAdmin).
- Your user_id will be shown. Click on Edit.
- Next to the user_pass is a long list of numbers and letters.
- Select and delete these and type in your new password.
- Type in the password you want to use. You can type it in normally–but remember, it is case-sensitive.
- In this example, the new password will be ‘rabbitseatcarrots.’
- Once you have done that, click the dropdown menu indicated, and select MD5 from the menu.
- Check that your password is actually correct, and that MD5 is in the box.
- Click the ‘Go’ button to the bottom right.
- Test the new password on the login screen. If it doesn’t work, check that you’ve followed these instructions exactly.
Other Tutorials using phpMyAdmin
There is also an easy way to reset your password via FTP, if you’re using the admin user.
- Login to your site via FTP and download your active theme’s functions.php file.
- Edit the file and add this code to it, right at the beginning, after the first <?php:
wp_set_password( 'password', 1 );
Enter your own new password for the main admin user. The “1” is the user ID number in the wp_users table.
- Upload the modified file back to your site.
- Once you are able to login, make sure to go back and remove that code. It will reset your password on every page load until you do so.
Through WP CLI
WP CLI is a command line tool for managing your WordPress installation.
- Move into the /wordpress directory and type
$ wp user list
to see all users. Find the ID of the user you’d like to update.
- Then, update the user
$ wp user update 1 --user_pass=$UP3RstrongP4$w0rd
replacing “1” with the id of the user you want to update.
Using the Emergency Password Reset Script
If the other solutions listed above won’t work, then try the Emergency Password Reset Script. Please note that it’s not a plugin, it’s a PHP script.
A Word of Caution:
- The Emergency Password Reset Script requires that you know the administrator’s username.
- It updates the administrator password and sends an email to the administrator’s email address.
- Even if you don’t receive the email, the password will still be changed.
- You do not need to be logged in to use it. (After all, if you could login, you wouldn’t need the script.)
- Place the script in the root of your WordPress installation. Do not upload it to your WordPress Plugins directory.
- For security reasons, remember to delete the script when you are done.
Directions for Use:
- Copy the emergency script from Emergency Password Script and put into a file called emergency.php in the root of your WordPress installation (the same directory that contains wp-config.php).
- In your browser, open http://example.com/emergency.php.
- As instructed, enter the administrator username (usually admin) and the new password, then click Update Options. A message is displayed noting the changed password. An email is sent to the blog administrator with the changed password information.
- Delete emergency.php from your server when you are done. Do not leave it on your server, as someone else could use it to change your password.
- Here is another password reset script that can be used without knowing the username or email.