{"id":22345,"date":"2026-08-27T15:47:53","date_gmt":"2026-08-27T13:47:53","guid":{"rendered":"https:\/\/www.curiaweb.ch\/?post_type=docs&#038;p=22345"},"modified":"2026-08-27T15:52:24","modified_gmt":"2026-08-27T13:52:24","password":"","slug":"manage-wordpress-users","status":"publish","type":"docs","link":"https:\/\/www.curiaweb.ch\/en\/hilfe\/wordpress\/wordpress-benutzer-verwalten\/","title":{"rendered":"Managing WordPress users: Properly setting up accounts, roles, and permissions"},"content":{"rendered":"<p class=\"wp-block-paragraph\">WordPress has built-in user management that allows multiple people to work on a website with their own login credentials. Not every user needs to be given full access to the entire website. Via various <strong>User roles and permissions<\/strong> it is possible to precisely define which tasks a person is allowed to perform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, an administrator can manage plugins and settings while an editor edits content or an author simply publishes their own posts. A sensibly configured user management therefore not only facilitates collaboration, but is also an important component of the <strong>WordPress Security<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this guide, we show you how to create users in WordPress, manage existing accounts, assign roles correctly, and securely remove users.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Briefly explained:<\/strong> You manage WordPress users under <strong>Users \u2192 All Users<\/strong>. You create new accounts under <strong>User \u2192 Add user<\/strong> The crucial factor here is the correct user role: Give each user only the permissions they need for their actual task.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Why are there different users in WordPress?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On a small website, only one person may work with WordPress. As soon as employees, editors, agencies, or external service providers are involved, however, they should not share the same administrator account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress therefore allows the creation of separate user accounts. Each user receives their own login credentials and a specific role.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This offers several advantages:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>every person has their own WordPress access<\/li>\n\n\n\n<li>Permissions can be specifically restricted<\/li>\n\n\n\n<li>not every user needs administrator rights<\/li>\n\n\n\n<li>Authors can be assigned to their own posts<\/li>\n\n\n\n<li>Accounts can be modified or removed individually<\/li>\n\n\n\n<li>In the event of personnel changes, there is no need to exchange a shared password<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Especially for business websites, a shared administrator account for multiple people is not a good solution.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where can I find the user management in WordPress?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">First, log in to the WordPress admin area.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is usually accessible on a standard WordPress installation at:<\/p>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/deine-domain.ch\/wp-admin\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Replace <code>your-domain.ch<\/code> through your actual domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then open:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Users \u2192 All Users<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There you can see the user accounts of your WordPress installation, provided your own user role is authorized to view or manage these accounts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">An overview of WordPress user roles<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress has several user roles by default. Each role has specific permissions, which in WordPress are called <strong>Capabilities<\/strong> be designated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The five classic roles of a standard WordPress installation are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Administrator<\/strong><\/li>\n\n\n\n<li><strong>Editor<\/strong><\/li>\n\n\n\n<li><strong>Author<\/strong><\/li>\n\n\n\n<li><strong>Employees<\/strong><\/li>\n\n\n\n<li><strong>Subscriber<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Plugins can add additional roles and permissions. With WooCommerce, for example, you can find additional roles that are not present in a standard WordPress installation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Administrator: Full control of the website<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Administrator<\/strong> has very extensive permissions in a standard single WordPress installation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Administrators can, among other things:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Manage users<\/li>\n\n\n\n<li>Install, activate and delete plugins<\/li>\n\n\n\n<li>Install and manage themes<\/li>\n\n\n\n<li>Change website settings<\/li>\n\n\n\n<li>Manage posts and pages<\/li>\n\n\n\n<li>Edit other users' content<\/li>\n\n\n\n<li>Update WordPress<\/li>\n\n\n\n<li>make far-reaching changes to the website<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Administrator rights should therefore only be granted to individuals who actually need these permissions.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Important:<\/strong> Do not grant administrator rights out of convenience. An administrator can modify essential parts of the website. If an administrator account is compromised, an attacker correspondingly possesses far-reaching capabilities.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Editor: Manage content of the entire website<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The role <strong>Editor<\/strong> is intended for people who will be working extensively on a website's content from an editorial perspective without having to handle the technical administration at the same time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Editors can in particular manage and publish their own and other contributions. They can also manage pages and comments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In contrast, an editor does not need administrator rights just because they are supposed to edit all blog posts on a website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For an employee who is responsible for the editorial maintenance of a website, this role may therefore be much more suitable than the administrator role.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Author: Create and publish your own posts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>Author<\/strong> can create, edit, and publish own posts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This role is suitable, for example, for a multi-author blog where each author is allowed to publish their own content independently, but does not need access to other authors' posts or the technical configuration of the website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This gives an author significantly fewer rights than an editor or administrator.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Employee: Write posts, but do not publish them yourself<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The role <strong>Employees<\/strong> is suitable for users who are allowed to create and edit their own posts, but should not publish them themselves.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Such a user can, for example, prepare a new article. The publication is then handled by a user with the necessary permissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This division of roles is practical if content needs to be internally reviewed or approved prior to publication.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Subscriber: Heavily restricted user access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Subscriber<\/strong> has very limited permissions by default. He can log in and manage his own profile, but does not have normal editorial or administrative rights to edit the website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whether this role is needed on your website at all depends on the respective project.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Which WordPress role should I assign?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When selecting a user role, a simple security principle applies: <strong>As many rights as necessary, but as few as possible.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A user who is only supposed to write blog posts does not need administrator rights. Similarly, an external copywriter usually does not need access to plugins, themes, or core WordPress settings.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Typical assignment of tasks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Manage website technically:<\/strong> Administrator<\/li>\n\n\n\n<li><strong>Manage entire editorial office:<\/strong> Editor<\/li>\n\n\n\n<li><strong>Self-publishing your own posts:<\/strong> Author<\/li>\n\n\n\n<li><strong>Prepare own posts, approval required:<\/strong> Employees<\/li>\n\n\n\n<li><strong>Only own profile or restricted access:<\/strong> Subscriber<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This assignment serves as a guide for a standard WordPress installation. Plugins can modify roles and permissions or add additional roles.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Create new user in WordPress<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If another person needs access to your WordPress website, you should create a separate user account for them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To do this, open:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>User \u2192 Add user<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Create new WordPress user<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log in to WordPress with an appropriately authorized account.<\/li>\n\n\n\n<li>Open <strong>User \u2192 Add user<\/strong>.<\/li>\n\n\n\n<li>Give a <strong>Usernames<\/strong> one.<\/li>\n\n\n\n<li>Carry the <strong>Email address<\/strong> of the new user.<\/li>\n\n\n\n<li>Add first name, last name, and additional information if necessary.<\/li>\n\n\n\n<li>Set the desired <strong>User role<\/strong> celebration.<\/li>\n\n\n\n<li>Check all information.<\/li>\n\n\n\n<li>Click on <strong>Add new user<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The exact appearance of individual options may vary slightly depending on your WordPress version and installed plugins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What username should I use?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The username is used to identify the WordPress account and can be used for logging in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Choose a unique username and do not use the same generic login for all administrators.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For multiple people, a clear assignment makes sense. This makes it easier to see later which account belongs to which person.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The username is also not the same as an author's publicly displayed name. WordPress allows you to set a separate display name.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Username and display name are not the same<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress distinguishes between the actual <strong>Usernames<\/strong> and the name that can be displayed, for example, on published posts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the user profile, among other things, first name, last name, nickname, and the public display name can be configured.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that the internal username does not necessarily have to appear publicly as the author name.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Secure password for a new user<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every WordPress user should use their own strong and unique password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not use shared passwords for multiple users and avoid passwords that are already used for other services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress can automatically generate strong passwords. A password manager is recommended for the secure management of various access credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We explain in detail how a user can change their own password in the WordPress dashboard in the article <a href=\"\/en\/help\/wordpress\/change-wordpress-admin-password\/\">Change WordPress password: Securely update admin password in dashboard<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Edit existing WordPress users<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Existing users can be found at:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Users \u2192 All Users<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Move the mouse pointer over the desired user or open their profile. Depending on your own permissions, you can then edit various account settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This may include, for example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>First name and last name<\/li>\n\n\n\n<li>Nickname<\/li>\n\n\n\n<li>public display name<\/li>\n\n\n\n<li>Email address<\/li>\n\n\n\n<li>Website<\/li>\n\n\n\n<li>biographical details<\/li>\n\n\n\n<li>User role<\/li>\n\n\n\n<li>Password<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Which settings are actually available depends on your permissions and the extensions installed on the website.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Change user role retroactively<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Tasks within a company or project can change. Therefore, the role of a WordPress user can be adjusted later if you have the appropriate permissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, if an author is to manage the entire editorial team in the future, a different role may be required. Conversely, permissions that are no longer needed should also be removed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before making a change, carefully check what additional privileges the new role receives.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Security principle:<\/strong> User permissions should not only be expanded, but also reduced again when tasks change. A user should permanently have only the permissions they actually need.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Why not just give everyone administrator rights?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">That might be convenient, but it is a poor security strategy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An administrator can make profound changes to WordPress. The more administrator accounts exist, the more accounts need to be protected accordingly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, the risk of accidental changes increases. For example, a user who is only supposed to edit content does not need to be able to deactivate plugins, switch themes, or change core settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Administrator rights should therefore be restricted to the smallest and most clearly defined group of people possible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Separate user accounts instead of a shared administrator login<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Multiple employees should not permanently work with the same administrator username and password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Separate user accounts make sense for several reasons:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Each user has their own login credentials<\/li>\n\n\n\n<li>Roles can be assigned individually<\/li>\n\n\n\n<li>an individual account can be specifically deactivated or removed<\/li>\n\n\n\n<li>Passwords do not need to be shared between multiple people<\/li>\n\n\n\n<li>Authors and content can be assigned to individual users.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For example, if an employee leaves the company, their user account can be removed without having to change the access credentials of all other users at the same time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Delete user from WordPress<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a user is no longer needed, you can delete their account provided you have the appropriate permissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To do this, open:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Users \u2192 All Users<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Select the relevant user and then the delete function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now comes an important point: If the user has already created content, WordPress asks when deleting, <strong>what should happen to this content<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What happens to the posts of a deleted user?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When deleting a user with existing content, WordPress fundamentally provides the option to either delete their content as well or assign it to another user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You should not make this decision rashly.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Attention:<\/strong> If you choose the option to delete a user's content when deleting a user, the content associated with that user can be removed. If you want to keep posts or other relevant content, assign them to another user before or during the deletion process.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Especially when an employee leaves, you usually only want to remove the user account and keep the published company content.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Delete user and reassign content to another user<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Safely remove user<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open <strong>Users \u2192 All Users<\/strong>.<\/li>\n\n\n\n<li>Check the user to be removed.<\/li>\n\n\n\n<li>Check if important content is assigned to this user.<\/li>\n\n\n\n<li>Choose <strong>Delete<\/strong>.<\/li>\n\n\n\n<li>Decide whether existing content should be deleted or assigned to another user.<\/li>\n\n\n\n<li>For required content, select a suitable existing user as the new author.<\/li>\n\n\n\n<li>Confirm the deletion process only after careful review.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Bei wichtigen Websites empfiehlt sich vor umfangreichen \u00c4nderungen an Benutzern und Inhalten grunds\u00e4tzlich eine aktuelle Datensicherung.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Was tun, wenn ein Mitarbeiter das Unternehmen verl\u00e4sst?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Bei einem Austritt sollte der WordPress-Zugang nicht unn\u00f6tig aktiv bleiben.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check in particular:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ben\u00f6tigt die Person weiterhin Zugriff?<\/li>\n\n\n\n<li>besitzt sie Administratorrechte?<\/li>\n\n\n\n<li>welche Inhalte sind dem Benutzer zugeordnet?<\/li>\n\n\n\n<li>m\u00fcssen Beitr\u00e4ge einem anderen Benutzer \u00fcbertragen werden?<\/li>\n\n\n\n<li>existieren weitere Zug\u00e4nge ausserhalb von WordPress?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Der letzte Punkt ist wichtig. Ein WordPress-Benutzerkonto ist nicht automatisch identisch mit anderen Zug\u00e4ngen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Eine Person kann zus\u00e4tzlich Zugriff auf cPanel, FTP, E-Mail-Konten, externe Dienste oder das CURIAWEB Kundencenter besitzen. Das L\u00f6schen des WordPress-Benutzers entfernt solche separaten Zug\u00e4nge nicht.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WordPress-Benutzer und cPanel-Benutzer sind getrennt<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ein h\u00e4ufiger Irrtum besteht darin, WordPress-Benutzer mit Hosting-Zug\u00e4ngen gleichzusetzen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ein WordPress-Benutzer wird innerhalb der WordPress-Installation verwaltet. cPanel ist dagegen die technische Verwaltungsoberfl\u00e4che des Hosting-Pakets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wenn du einen WordPress-Benutzer l\u00f6schst, wird dadurch beispielsweise kein FTP-Konto und kein E-Mail-Postfach in cPanel gel\u00f6scht.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dasselbe gilt umgekehrt: Eine \u00c4nderung des cPanel-Passworts ver\u00e4ndert nicht automatisch das Passwort eines WordPress-Benutzers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Benutzer kann sich nicht mehr anmelden<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Wenn ein bestehender Benutzer sein Passwort vergessen hat, musst du nicht zwingend das gesamte Benutzerkonto l\u00f6schen und neu erstellen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress besitzt eine integrierte Passwort-Wiederherstellung. \u00dcber die Login-Seite kann der Benutzer einen Link zum Zur\u00fccksetzen seines Passworts anfordern.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Die Login-Seite befindet sich normalerweise unter:<\/p>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/deine-domain.ch\/wp-login.php\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Den vollst\u00e4ndigen Ablauf erkl\u00e4ren wir in der Anleitung <a href=\"\/en\/help\/wordpress\/recover-wordpress-admin-password\/\">WordPress-Admin-Passwort vergessen: Zugang wiederherstellen<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Was tun, wenn die Passwort-E-Mail nicht ankommt?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Wenn ein Benutzer die E-Mail zur Passwort-Wiederherstellung nicht erh\u00e4lt, sollte zun\u00e4chst die hinterlegte E-Mail-Adresse sowie der Spam-Ordner gepr\u00fcft werden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Werden WordPress-Systemnachrichten generell nicht zuverl\u00e4ssig zugestellt, kann die Konfiguration des E-Mail-Versands die Ursache sein.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bei CURIAWEB steht daf\u00fcr <strong>GoSMTP PRO free<\/strong> zur Verf\u00fcgung. Damit l\u00e4sst sich der Versand von WordPress-E-Mails \u00fcber SMTP konfigurieren.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wie das funktioniert, zeigen wir in der Anleitung <a href=\"\/en\/help\/wordpress\/how-to-set-up-wordpress-smtp\/\">Send WordPress emails via SMTP<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Benutzerverwaltung bei einem Blog mit mehreren Autoren<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Bei einem Blog mit mehreren Autoren ist die WordPress-Benutzerverwaltung besonders praktisch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jeder Autor kann ein eigenes Konto erhalten. Dadurch k\u00f6nnen Beitr\u00e4ge eindeutig einem bestimmten Autor zugeordnet werden, ohne dass alle Personen denselben WordPress-Zugang verwenden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Je nach redaktionellem Ablauf kannst du beispielsweise Autoren einsetzen, die ihre Beitr\u00e4ge selbst ver\u00f6ffentlichen d\u00fcrfen, oder Mitarbeiter, deren Beitr\u00e4ge vor der Ver\u00f6ffentlichung durch einen Redakteur gepr\u00fcft werden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wie du neue Beitr\u00e4ge erstellst, behandeln wir ausf\u00fchrlich im Artikel <a href=\"\/en\/help\/wordpress\/create-blog-posts\/\">Blogbeitr\u00e4ge in WordPress erstellen<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Benutzerverwaltung bei Unternehmenswebsites<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Auch bei einer normalen Unternehmenswebsite ist eine klare Rollenverteilung sinnvoll.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ein m\u00f6gliches Beispiel:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>die f\u00fcr die technische Website-Verwaltung verantwortliche Person erh\u00e4lt Administratorrechte<\/li>\n\n\n\n<li>die Marketingabteilung arbeitet als Redakteur<\/li>\n\n\n\n<li>ein externer Texter arbeitet als Autor oder Mitarbeiter<\/li>\n\n\n\n<li>nicht mehr beteiligte Personen verlieren ihren Zugang<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Welche Rollen tats\u00e4chlich sinnvoll sind, h\u00e4ngt immer davon ab, welche Aufgaben die einzelnen Personen \u00fcbernehmen.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Plugins k\u00f6nnen zus\u00e4tzliche Benutzerrollen hinzuf\u00fcgen<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Die f\u00fcnf Standardrollen sind nicht die einzigen Rollen, die dir auf einer WordPress-Website begegnen k\u00f6nnen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Plugins k\u00f6nnen eigene Benutzerrollen und zus\u00e4tzliche Berechtigungen registrieren. Das ist beispielsweise bei Shop-, Mitglieder-, Lernplattform- oder Community-L\u00f6sungen \u00fcblich.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Installierst du entsprechende Erweiterungen, k\u00f6nnen deshalb unter <strong>Benutzer<\/strong> zus\u00e4tzliche Rollen erscheinen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bevor du einem Benutzer eine solche Rolle zuweist, solltest du pr\u00fcfen, welche Berechtigungen damit tats\u00e4chlich verbunden sind.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WordPress-Benutzer bei WooCommerce<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">WooCommerce erweitert die WordPress-Benutzerverwaltung unter anderem um zus\u00e4tzliche Rollen f\u00fcr den Shopbetrieb. Dadurch k\u00f6nnen beispielsweise Kundenkonten von normalen redaktionellen WordPress-Benutzern unterschieden werden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bei einem WooCommerce-Shop solltest du Benutzer deshalb nicht allein anhand ihres Namens beurteilen oder un\u00fcberlegt l\u00f6schen. Pr\u00fcfe vorher, welche Rolle der Benutzer besitzt und ob das Konto mit Bestellungen oder Kundendaten zusammenh\u00e4ngt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Insbesondere bei produktiven Shops sollte die Benutzerverwaltung mit entsprechender Sorgfalt erfolgen.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Benutzerrechte regelm\u00e4ssig \u00fcberpr\u00fcfen<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Mit der Zeit sammeln sich auf \u00e4lteren WordPress-Websites h\u00e4ufig Benutzerkonten an, die urspr\u00fcnglich f\u00fcr Mitarbeiter, Agenturen, Entwickler oder andere externe Personen eingerichtet wurden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Solche Konten werden leicht vergessen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Es ist deshalb sinnvoll, die Benutzerliste gelegentlich zu kontrollieren:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Welche Benutzer existieren?<\/li>\n\n\n\n<li>Wer ben\u00f6tigt tats\u00e4chlich noch Zugriff?<\/li>\n\n\n\n<li>Wer besitzt Administratorrechte?<\/li>\n\n\n\n<li>Sind die vergebenen Rollen noch angemessen?<\/li>\n\n\n\n<li>Existieren Konten ehemaliger Mitarbeiter oder Dienstleister?<\/li>\n\n\n\n<li>Sind ungew\u00f6hnliche oder unbekannte Benutzer vorhanden?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Besonders Administrator-Konten verdienen dabei Aufmerksamkeit.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Practical Tip:<\/strong> Wenn du einen Benutzer nicht kennst, l\u00f6sche ihn nicht sofort. Pr\u00fcfe zuerst, wem das Konto geh\u00f6rt, welche Rolle es besitzt und welche Inhalte damit verbunden sind. Ein unbekannt wirkender Benutzer kann beispielsweise zu einem Plugin, einer fr\u00fcheren Agentur oder einem legitimen technischen Prozess geh\u00f6ren.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Unbekannter Administrator entdeckt: Was tun?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Findest du ein Administrator-Konto, das definitiv niemandem zugeordnet werden kann, solltest du die Situation genauer untersuchen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ein unbekannter Administrator kann ein Hinweis auf einen unbefugten Zugriff sein. Gleichzeitig solltest du nicht vorschnell \u00c4nderungen durchf\u00fchren, ohne die Herkunft des Kontos zu pr\u00fcfen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kontrolliere in einem solchen Fall unter anderem:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>welche E-Mail-Adresse beim Benutzer hinterlegt ist<\/li>\n\n\n\n<li>ob das Konto einer bekannten Person oder Agentur geh\u00f6rt<\/li>\n\n\n\n<li>ob weitere unbekannte Benutzer vorhanden sind<\/li>\n\n\n\n<li>ob ungew\u00f6hnliche Plugins installiert wurden<\/li>\n\n\n\n<li>ob Inhalte oder Einstellungen ver\u00e4ndert wurden<\/li>\n\n\n\n<li>ob andere Administrator-Konten noch sicher sind<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Bei einem konkreten Verdacht auf eine kompromittierte Website sollte nicht nur der unbekannte Benutzer entfernt werden. Die gesamte WordPress-Installation sollte auf weitere Manipulationen gepr\u00fcft werden.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vor gr\u00f6sseren \u00c4nderungen ein Backup erstellen<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Das Anlegen eines normalen Benutzers ist keine besonders riskante \u00c4nderung. Anders sieht es aus, wenn mehrere Benutzer gel\u00f6scht, Rollen umfangreich ver\u00e4ndert oder bestehende Inhalte neu zugeordnet werden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Vor solchen \u00c4nderungen ist eine aktuelle Sicherung sinnvoll.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Das gilt insbesondere f\u00fcr Websites mit vielen Autoren, umfangreichen Inhalten oder einem produktiven WooCommerce-Shop.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Typische Fehler bei der WordPress-Benutzerverwaltung<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Viele Sicherheits- und Verwaltungsprobleme entstehen nicht durch WordPress selbst, sondern durch unn\u00f6tig grossz\u00fcgig vergebene Berechtigungen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Common mistakes include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>jedem Benutzer Administratorrechte geben<\/li>\n\n\n\n<li>einen gemeinsamen Administrator-Zugang f\u00fcr mehrere Personen verwenden<\/li>\n\n\n\n<li>ehemalige Mitarbeiterkonten aktiv lassen<\/li>\n\n\n\n<li>Passw\u00f6rter zwischen mehreren Benutzern teilen<\/li>\n\n\n\n<li>Benutzer l\u00f6schen, ohne vorher deren Inhalte zu pr\u00fcfen<\/li>\n\n\n\n<li>beim L\u00f6schen versehentlich ben\u00f6tigte Beitr\u00e4ge entfernen<\/li>\n\n\n\n<li>Plugin-spezifische Benutzerrollen ignorieren<\/li>\n\n\n\n<li>WordPress-Zug\u00e4nge mit cPanel-, FTP- oder E-Mail-Zug\u00e4ngen verwechseln<\/li>\n\n\n\n<li>unbekannte Administratoren nicht untersuchen<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> Nicht jeder, der an einer WordPress-Website arbeitet, muss Administrator sein. Eine saubere Rollenverteilung reduziert unn\u00f6tige Zugriffsrechte und damit auch das Risiko versehentlicher oder unbefugter \u00c4nderungen.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You manage WordPress users under <strong>Users \u2192 All Users<\/strong>. Neue Konten kannst du unter <strong>User \u2192 Add user<\/strong> erstellen und mit einer passenden Benutzerrolle ausstatten.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress unterscheidet standardm\u00e4ssig zwischen <strong>Administrator, Redakteur, Autor, Mitarbeiter und Abonnent<\/strong>. Welche Rolle ein Benutzer erh\u00e4lt, sollte sich nach seinen tats\u00e4chlichen Aufgaben richten. Vergib insbesondere Administratorrechte nur dann, wenn sie wirklich ben\u00f6tigt werden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wenn du einen Benutzer l\u00f6schst, pr\u00fcfe vorher unbedingt dessen Inhalte. WordPress kann dir beim L\u00f6schen die M\u00f6glichkeit geben, vorhandene Inhalte einem anderen Benutzer zuzuordnen. Dadurch lassen sich beispielsweise Beitr\u00e4ge eines ehemaligen Mitarbeiters behalten, obwohl dessen Zugang entfernt wird.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Weitere wichtige Anleitungen zur Benutzerverwaltung findest du in unseren Artikeln zum <a href=\"\/en\/help\/wordpress\/change-wordpress-admin-password\/\">\u00c4ndern des WordPress-Passworts<\/a>, zur <a href=\"\/en\/help\/wordpress\/recover-wordpress-admin-password\/\">Wiederherstellung eines vergessenen WordPress-Passworts<\/a> und zur <a href=\"\/en\/help\/wordpress\/how-to-set-up-wordpress-smtp\/\">Einrichtung des WordPress-E-Mail-Versands per SMTP<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>WordPress besitzt eine integrierte Benutzerverwaltung, mit der mehrere Personen mit eigenen Zugangsdaten an einer Website arbeiten k\u00f6nnen. Dabei muss nicht jeder Benutzer vollst\u00e4ndigen Zugriff auf die gesamte Website erhalten. \u00dcber verschiedene Benutzerrollen und Berechtigungen l\u00e4sst sich genau festlegen, welche Aufgaben eine Person ausf\u00fchren darf. So kann beispielsweise ein Administrator Plugins und Einstellungen verwalten, w\u00e4hrend ein [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_joinchat":[],"footnotes":""},"doc_category":[80],"doc_tag":[],"class_list":["post-22345","docs","type-docs","status-publish","hentry","doc_category-wordpress"],"year_month":"2026-09","word_count":2990,"total_views":"5","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"Silvio Mazenauer","author_nicename":"admin-curia","author_url":"https:\/\/www.curiaweb.ch\/en\/author\/admin-curia\/"},"doc_category_info":[{"term_name":"WordPress","term_url":"https:\/\/www.curiaweb.ch\/en\/hilfe-kategorie\/wordpress\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs\/22345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/comments?post=22345"}],"version-history":[{"count":1,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs\/22345\/revisions"}],"predecessor-version":[{"id":22347,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs\/22345\/revisions\/22347"}],"wp:attachment":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/media?parent=22345"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/doc_category?post=22345"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/doc_tag?post=22345"}],"curies":[{"name":"WP","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}