WordPress has built-in user management that allows multiple people to work on a website with their own login credentials. Not every user needs to be given full access to the entire website. Via various User roles and permissions it is possible to precisely define which tasks a person is allowed to perform.
For example, an administrator can manage plugins and settings while an editor edits content or an author simply publishes their own posts. A sensibly configured user management therefore not only facilitates collaboration, but is also an important component of the WordPress Security.
In this guide, we show you how to create users in WordPress, manage existing accounts, assign roles correctly, and securely remove users.
Briefly explained: You manage WordPress users under Users → All Users. You create new accounts under User → Add user The crucial factor here is the correct user role: Give each user only the permissions they need for their actual task.
Why are there different users in WordPress? #
On a small website, only one person may work with WordPress. As soon as employees, editors, agencies, or external service providers are involved, however, they should not share the same administrator account.
WordPress therefore allows the creation of separate user accounts. Each user receives their own login credentials and a specific role.
This offers several advantages:
- every person has their own WordPress access
- Permissions can be specifically restricted
- not every user needs administrator rights
- Authors can be assigned to their own posts
- Accounts can be modified or removed individually
- In the event of personnel changes, there is no need to exchange a shared password
Especially for business websites, a shared administrator account for multiple people is not a good solution.
Where can I find the user management in WordPress? #
First, log in to the WordPress admin area.
This is usually accessible on a standard WordPress installation at:
Replace your-domain.ch through your actual domain.
Then open:
Users → All Users
There you can see the user accounts of your WordPress installation, provided your own user role is authorized to view or manage these accounts.
An overview of WordPress user roles #
WordPress has several user roles by default. Each role has specific permissions, which in WordPress are called Capabilities be designated.
The five classic roles of a standard WordPress installation are:
- Administrator
- Editor
- Author
- Employees
- Subscriber
Plugins can add additional roles and permissions. With WooCommerce, for example, you can find additional roles that are not present in a standard WordPress installation.
Administrator: Full control of the website #
The Administrator has very extensive permissions in a standard single WordPress installation.
Administrators can, among other things:
- Manage users
- Install, activate and delete plugins
- Install and manage themes
- Change website settings
- Manage posts and pages
- Edit other users' content
- Update WordPress
- make far-reaching changes to the website
Administrator rights should therefore only be granted to individuals who actually need these permissions.
Important: Do not grant administrator rights out of convenience. An administrator can modify essential parts of the website. If an administrator account is compromised, an attacker correspondingly possesses far-reaching capabilities.
Editor: Manage content of the entire website #
The role Editor is intended for people who will be working extensively on a website's content from an editorial perspective without having to handle the technical administration at the same time.
Editors can in particular manage and publish their own and other contributions. They can also manage pages and comments.
In contrast, an editor does not need administrator rights just because they are supposed to edit all blog posts on a website.
For an employee who is responsible for the editorial maintenance of a website, this role may therefore be much more suitable than the administrator role.
Author: Create and publish your own posts #
A Author can create, edit, and publish own posts.
This role is suitable, for example, for a multi-author blog where each author is allowed to publish their own content independently, but does not need access to other authors' posts or the technical configuration of the website.
This gives an author significantly fewer rights than an editor or administrator.
Employee: Write posts, but do not publish them yourself #
The role Employees is suitable for users who are allowed to create and edit their own posts, but should not publish them themselves.
Such a user can, for example, prepare a new article. The publication is then handled by a user with the necessary permissions.
This division of roles is practical if content needs to be internally reviewed or approved prior to publication.
Subscriber: Heavily restricted user access #
The Subscriber has very limited permissions by default. He can log in and manage his own profile, but does not have normal editorial or administrative rights to edit the website.
Whether this role is needed on your website at all depends on the respective project.
Which WordPress role should I assign? #
When selecting a user role, a simple security principle applies: As many rights as necessary, but as few as possible.
A user who is only supposed to write blog posts does not need administrator rights. Similarly, an external copywriter usually does not need access to plugins, themes, or core WordPress settings.
Typical assignment of tasks #
- Manage website technically: Administrator
- Manage entire editorial office: Editor
- Self-publishing your own posts: Author
- Prepare own posts, approval required: Employees
- Only own profile or restricted access: Subscriber
This assignment serves as a guide for a standard WordPress installation. Plugins can modify roles and permissions or add additional roles.
Create new user in WordPress #
If another person needs access to your WordPress website, you should create a separate user account for them.
To do this, open:
User → Add user
Create new WordPress user #
- Log in to WordPress with an appropriately authorized account.
- Open User → Add user.
- Give a Usernames one.
- Carry the Email address of the new user.
- Add first name, last name, and additional information if necessary.
- Set the desired User role celebration.
- Check all information.
- Click on Add new user.
The exact appearance of individual options may vary slightly depending on your WordPress version and installed plugins.
What username should I use? #
The username is used to identify the WordPress account and can be used for logging in.
Choose a unique username and do not use the same generic login for all administrators.
For multiple people, a clear assignment makes sense. This makes it easier to see later which account belongs to which person.
The username is also not the same as an author's publicly displayed name. WordPress allows you to set a separate display name.
Username and display name are not the same #
WordPress distinguishes between the actual Usernames and the name that can be displayed, for example, on published posts.
In the user profile, among other things, first name, last name, nickname, and the public display name can be configured.
This means that the internal username does not necessarily have to appear publicly as the author name.
Secure password for a new user #
Every WordPress user should use their own strong and unique password.
Do not use shared passwords for multiple users and avoid passwords that are already used for other services.
WordPress can automatically generate strong passwords. A password manager is recommended for the secure management of various access credentials.
We explain in detail how a user can change their own password in the WordPress dashboard in the article Change WordPress password: Securely update admin password in dashboard.
Edit existing WordPress users #
Existing users can be found at:
Users → All Users
Move the mouse pointer over the desired user or open their profile. Depending on your own permissions, you can then edit various account settings.
This may include, for example:
- First name and last name
- Nickname
- public display name
- Email address
- Website
- biographical details
- User role
- Password
Which settings are actually available depends on your permissions and the extensions installed on the website.
Change user role retroactively #
Tasks within a company or project can change. Therefore, the role of a WordPress user can be adjusted later if you have the appropriate permissions.
For example, if an author is to manage the entire editorial team in the future, a different role may be required. Conversely, permissions that are no longer needed should also be removed.
Before making a change, carefully check what additional privileges the new role receives.
Security principle: User permissions should not only be expanded, but also reduced again when tasks change. A user should permanently have only the permissions they actually need.
Why not just give everyone administrator rights? #
That might be convenient, but it is a poor security strategy.
An administrator can make profound changes to WordPress. The more administrator accounts exist, the more accounts need to be protected accordingly.
Furthermore, the risk of accidental changes increases. For example, a user who is only supposed to edit content does not need to be able to deactivate plugins, switch themes, or change core settings.
Administrator rights should therefore be restricted to the smallest and most clearly defined group of people possible.
Separate user accounts instead of a shared administrator login #
Multiple employees should not permanently work with the same administrator username and password.
Separate user accounts make sense for several reasons:
- Each user has their own login credentials
- Roles can be assigned individually
- an individual account can be specifically deactivated or removed
- Passwords do not need to be shared between multiple people
- Authors and content can be assigned to individual users.
For example, if an employee leaves the company, their user account can be removed without having to change the access credentials of all other users at the same time.
Delete user from WordPress #
If a user is no longer needed, you can delete their account provided you have the appropriate permissions.
To do this, open:
Users → All Users
Select the relevant user and then the delete function.
Now comes an important point: If the user has already created content, WordPress asks when deleting, what should happen to this content.
What happens to the posts of a deleted user? #
When deleting a user with existing content, WordPress fundamentally provides the option to either delete their content as well or assign it to another user.
You should not make this decision rashly.
Attention: If you choose the option to delete a user's content when deleting a user, the content associated with that user can be removed. If you want to keep posts or other relevant content, assign them to another user before or during the deletion process.
Especially when an employee leaves, you usually only want to remove the user account and keep the published company content.
Delete user and reassign content to another user #
Safely remove user #
- Open Users → All Users.
- Check the user to be removed.
- Check if important content is assigned to this user.
- Choose Delete.
- Decide whether existing content should be deleted or assigned to another user.
- For required content, select a suitable existing user as the new author.
- Confirm the deletion process only after careful review.
Bei wichtigen Websites empfiehlt sich vor umfangreichen Änderungen an Benutzern und Inhalten grundsätzlich eine aktuelle Datensicherung.
Was tun, wenn ein Mitarbeiter das Unternehmen verlässt? #
Bei einem Austritt sollte der WordPress-Zugang nicht unnötig aktiv bleiben.
Check in particular:
- benötigt die Person weiterhin Zugriff?
- besitzt sie Administratorrechte?
- welche Inhalte sind dem Benutzer zugeordnet?
- müssen Beiträge einem anderen Benutzer übertragen werden?
- existieren weitere Zugänge ausserhalb von WordPress?
Der letzte Punkt ist wichtig. Ein WordPress-Benutzerkonto ist nicht automatisch identisch mit anderen Zugängen.
Eine Person kann zusätzlich Zugriff auf cPanel, FTP, E-Mail-Konten, externe Dienste oder das CURIAWEB Kundencenter besitzen. Das Löschen des WordPress-Benutzers entfernt solche separaten Zugänge nicht.
WordPress-Benutzer und cPanel-Benutzer sind getrennt #
Ein häufiger Irrtum besteht darin, WordPress-Benutzer mit Hosting-Zugängen gleichzusetzen.
Ein WordPress-Benutzer wird innerhalb der WordPress-Installation verwaltet. cPanel ist dagegen die technische Verwaltungsoberfläche des Hosting-Pakets.
Wenn du einen WordPress-Benutzer löschst, wird dadurch beispielsweise kein FTP-Konto und kein E-Mail-Postfach in cPanel gelöscht.
Dasselbe gilt umgekehrt: Eine Änderung des cPanel-Passworts verändert nicht automatisch das Passwort eines WordPress-Benutzers.
Benutzer kann sich nicht mehr anmelden #
Wenn ein bestehender Benutzer sein Passwort vergessen hat, musst du nicht zwingend das gesamte Benutzerkonto löschen und neu erstellen.
WordPress besitzt eine integrierte Passwort-Wiederherstellung. Über die Login-Seite kann der Benutzer einen Link zum Zurücksetzen seines Passworts anfordern.
Die Login-Seite befindet sich normalerweise unter:
Den vollständigen Ablauf erklären wir in der Anleitung WordPress-Admin-Passwort vergessen: Zugang wiederherstellen.
Was tun, wenn die Passwort-E-Mail nicht ankommt? #
Wenn ein Benutzer die E-Mail zur Passwort-Wiederherstellung nicht erhält, sollte zunächst die hinterlegte E-Mail-Adresse sowie der Spam-Ordner geprüft werden.
Werden WordPress-Systemnachrichten generell nicht zuverlässig zugestellt, kann die Konfiguration des E-Mail-Versands die Ursache sein.
Bei CURIAWEB steht dafür GoSMTP PRO free zur Verfügung. Damit lässt sich der Versand von WordPress-E-Mails über SMTP konfigurieren.
Wie das funktioniert, zeigen wir in der Anleitung Send WordPress emails via SMTP.
Benutzerverwaltung bei einem Blog mit mehreren Autoren #
Bei einem Blog mit mehreren Autoren ist die WordPress-Benutzerverwaltung besonders praktisch.
Jeder Autor kann ein eigenes Konto erhalten. Dadurch können Beiträge eindeutig einem bestimmten Autor zugeordnet werden, ohne dass alle Personen denselben WordPress-Zugang verwenden.
Je nach redaktionellem Ablauf kannst du beispielsweise Autoren einsetzen, die ihre Beiträge selbst veröffentlichen dürfen, oder Mitarbeiter, deren Beiträge vor der Veröffentlichung durch einen Redakteur geprüft werden.
Wie du neue Beiträge erstellst, behandeln wir ausführlich im Artikel Blogbeiträge in WordPress erstellen.
Benutzerverwaltung bei Unternehmenswebsites #
Auch bei einer normalen Unternehmenswebsite ist eine klare Rollenverteilung sinnvoll.
Ein mögliches Beispiel:
- die für die technische Website-Verwaltung verantwortliche Person erhält Administratorrechte
- die Marketingabteilung arbeitet als Redakteur
- ein externer Texter arbeitet als Autor oder Mitarbeiter
- nicht mehr beteiligte Personen verlieren ihren Zugang
Welche Rollen tatsächlich sinnvoll sind, hängt immer davon ab, welche Aufgaben die einzelnen Personen übernehmen.
Plugins können zusätzliche Benutzerrollen hinzufügen #
Die fünf Standardrollen sind nicht die einzigen Rollen, die dir auf einer WordPress-Website begegnen können.
Plugins können eigene Benutzerrollen und zusätzliche Berechtigungen registrieren. Das ist beispielsweise bei Shop-, Mitglieder-, Lernplattform- oder Community-Lösungen üblich.
Installierst du entsprechende Erweiterungen, können deshalb unter Benutzer zusätzliche Rollen erscheinen.
Bevor du einem Benutzer eine solche Rolle zuweist, solltest du prüfen, welche Berechtigungen damit tatsächlich verbunden sind.
WordPress-Benutzer bei WooCommerce #
WooCommerce erweitert die WordPress-Benutzerverwaltung unter anderem um zusätzliche Rollen für den Shopbetrieb. Dadurch können beispielsweise Kundenkonten von normalen redaktionellen WordPress-Benutzern unterschieden werden.
Bei einem WooCommerce-Shop solltest du Benutzer deshalb nicht allein anhand ihres Namens beurteilen oder unüberlegt löschen. Prüfe vorher, welche Rolle der Benutzer besitzt und ob das Konto mit Bestellungen oder Kundendaten zusammenhängt.
Insbesondere bei produktiven Shops sollte die Benutzerverwaltung mit entsprechender Sorgfalt erfolgen.
Benutzerrechte regelmässig überprüfen #
Mit der Zeit sammeln sich auf älteren WordPress-Websites häufig Benutzerkonten an, die ursprünglich für Mitarbeiter, Agenturen, Entwickler oder andere externe Personen eingerichtet wurden.
Solche Konten werden leicht vergessen.
Es ist deshalb sinnvoll, die Benutzerliste gelegentlich zu kontrollieren:
- Welche Benutzer existieren?
- Wer benötigt tatsächlich noch Zugriff?
- Wer besitzt Administratorrechte?
- Sind die vergebenen Rollen noch angemessen?
- Existieren Konten ehemaliger Mitarbeiter oder Dienstleister?
- Sind ungewöhnliche oder unbekannte Benutzer vorhanden?
Besonders Administrator-Konten verdienen dabei Aufmerksamkeit.
Practical Tip: Wenn du einen Benutzer nicht kennst, lösche ihn nicht sofort. Prüfe zuerst, wem das Konto gehört, welche Rolle es besitzt und welche Inhalte damit verbunden sind. Ein unbekannt wirkender Benutzer kann beispielsweise zu einem Plugin, einer früheren Agentur oder einem legitimen technischen Prozess gehören.
Unbekannter Administrator entdeckt: Was tun? #
Findest du ein Administrator-Konto, das definitiv niemandem zugeordnet werden kann, solltest du die Situation genauer untersuchen.
Ein unbekannter Administrator kann ein Hinweis auf einen unbefugten Zugriff sein. Gleichzeitig solltest du nicht vorschnell Änderungen durchführen, ohne die Herkunft des Kontos zu prüfen.
Kontrolliere in einem solchen Fall unter anderem:
- welche E-Mail-Adresse beim Benutzer hinterlegt ist
- ob das Konto einer bekannten Person oder Agentur gehört
- ob weitere unbekannte Benutzer vorhanden sind
- ob ungewöhnliche Plugins installiert wurden
- ob Inhalte oder Einstellungen verändert wurden
- ob andere Administrator-Konten noch sicher sind
Bei einem konkreten Verdacht auf eine kompromittierte Website sollte nicht nur der unbekannte Benutzer entfernt werden. Die gesamte WordPress-Installation sollte auf weitere Manipulationen geprüft werden.
Vor grösseren Änderungen ein Backup erstellen #
Das Anlegen eines normalen Benutzers ist keine besonders riskante Änderung. Anders sieht es aus, wenn mehrere Benutzer gelöscht, Rollen umfangreich verändert oder bestehende Inhalte neu zugeordnet werden.
Vor solchen Änderungen ist eine aktuelle Sicherung sinnvoll.
Das gilt insbesondere für Websites mit vielen Autoren, umfangreichen Inhalten oder einem produktiven WooCommerce-Shop.
Typische Fehler bei der WordPress-Benutzerverwaltung #
Viele Sicherheits- und Verwaltungsprobleme entstehen nicht durch WordPress selbst, sondern durch unnötig grosszügig vergebene Berechtigungen.
Common mistakes include:
- jedem Benutzer Administratorrechte geben
- einen gemeinsamen Administrator-Zugang für mehrere Personen verwenden
- ehemalige Mitarbeiterkonten aktiv lassen
- Passwörter zwischen mehreren Benutzern teilen
- Benutzer löschen, ohne vorher deren Inhalte zu prüfen
- beim Löschen versehentlich benötigte Beiträge entfernen
- Plugin-spezifische Benutzerrollen ignorieren
- WordPress-Zugänge mit cPanel-, FTP- oder E-Mail-Zugängen verwechseln
- unbekannte Administratoren nicht untersuchen
Note: Nicht jeder, der an einer WordPress-Website arbeitet, muss Administrator sein. Eine saubere Rollenverteilung reduziert unnötige Zugriffsrechte und damit auch das Risiko versehentlicher oder unbefugter Änderungen.
Summary #
You manage WordPress users under Users → All Users. Neue Konten kannst du unter User → Add user erstellen und mit einer passenden Benutzerrolle ausstatten.
WordPress unterscheidet standardmässig zwischen Administrator, Redakteur, Autor, Mitarbeiter und Abonnent. Welche Rolle ein Benutzer erhält, sollte sich nach seinen tatsächlichen Aufgaben richten. Vergib insbesondere Administratorrechte nur dann, wenn sie wirklich benötigt werden.
Wenn du einen Benutzer löschst, prüfe vorher unbedingt dessen Inhalte. WordPress kann dir beim Löschen die Möglichkeit geben, vorhandene Inhalte einem anderen Benutzer zuzuordnen. Dadurch lassen sich beispielsweise Beiträge eines ehemaligen Mitarbeiters behalten, obwohl dessen Zugang entfernt wird.
Weitere wichtige Anleitungen zur Benutzerverwaltung findest du in unseren Artikeln zum Ändern des WordPress-Passworts, zur Wiederherstellung eines vergessenen WordPress-Passworts und zur Einrichtung des WordPress-E-Mail-Versands per SMTP.