• Plans & Pricing
  • Log in
  • Get started
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress 
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Get started
  • Sign up
  • Log in
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress  
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Jetpack App
  • Learn more
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Search
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Forums / prevent unauthorised users to gain access

prevent unauthorised users to gain access

  • Unknown's avatar
    zentie · Member · Feb 2, 2026 at 2:06 pm
    • Copy link Copy link
    • Add topic to favorites Add topic to favorites

    Someone recently gained access to my site without my authorisation. Please let me know how to prevent this in the future.

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar
    james3265166 · Member · Feb 2, 2026 at 3:19 pm
    • Copy link Copy link

    To secure your site after an unauthorized access event, you should immediately address the primary “entry points” hackers use: weak credentials and outdated software. First, you must change your administrative password and enable Two-Step Authentication (2FA) via the Security tab in your WordPress.com account profile; this ensures that even if someone steals your password, they cannot enter without a unique code from your phone. Next, audit your site’s users by going to Users > All Users to delete any accounts you don’t recognize, and check Settings > General to ensure the “Membership” box for “Anyone can register” is unchecked unless absolutely necessary. Since 96% of WordPress hacks occur through vulnerabilities in old plugins or themes, you should also navigate to Dashboard > Updates to ensure every component of your site is running its latest version, which includes the newest security patches. Finally, if your plan allows it, install a security plugin like Wordfence or Solid Security to perform a deep malware scan and set up a Web Application Firewall (WAF) to block suspicious traffic before it even reaches your login screen.

Log in or create an account to reply
Log in Sign Up

Tags

  • account
  • Jetpack

About this topic

  • In: Support
  • 2 participants
  • 1 reply
  • Last activity 11 hours
  • Latest reply from zentie

Couldn't find what you needed?

Contact us

Contact us

Get answers from our AI assistant, with access to 24/7 expert human support on paid plans.

Browse our guides

Browse our guides

Find step-by-step solutions to common questions in our comprehensive guides.

WordPress.com

Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Professional Email
  • Website Design Services
  • WordPress Studio
  • Enterprise WordPress
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Blog
  • Business Name Generator
  • Logo Maker
  • WordPress.com Reader
  • Accessibility
  • Remove Subscriptions
Help
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
  • Developer Resources
Company
  • About
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users
DeutschEspañolFrançaisBahasa IndonesiaItalianoNederlandsPortuguês do BrasilSvenskaTürkçeРусскийالعربيةעִבְרִית日本語한국어简体中文繁體中文English

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Facebook
  • WordPress.com on X (Twitter)
  • WordPress.com on Instagram
  • WordPress.com on YouTube

Automattic

Automattic
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions