Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FTP does not create a WordPress account by itself. It lets you place a temporary PHP snippet in the active theme; when WordPress loads a page, that snippet calls WordPress’s user API, creates the account, and assigns the administrator role. Remove the snippet immediately after you regain access.

Before you begin

  • Confirm that you are authorized to administer the site.
  • Make a current backup of the file you will edit, and preferably a full site backup.
  • Have the site’s FTP or SFTP credentials, a unique temporary password, and an email address you control.
  • Use SFTP when your host provides it; it encrypts the connection. The WordPress procedure is otherwise the same.

If the WordPress dashboard still works, use Users > Add New instead. FTP is primarily a recovery or maintenance route when you cannot use the dashboard.

Find the active theme’s functions.php file

  1. Connect to the site with your FTP/SFTP client.
  2. Open the WordPress installation directory. The directory normally contains wp-admin, wp-content, and wp-includes.
  3. Browse to wp-content/themes/<active-theme>/.
  4. Download that theme’s functions.php file and keep the untouched copy as your rollback file.

Edit the active theme, not an inactive theme. A child theme, multisite setup, must-use plugin, security plugin, or caching layer can change where code runs or whether a request reaches it; treat those as site-specific checks.

Add a guarded, temporary creation snippet

Open the downloaded functions.php in a plain-text or code editor. Add the snippet near the end of the file, before a closing ?> tag if one is present. Do not add a second opening <?php tag inside an already-open PHP file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
<?php
add_action('init', function () {
    $username = 'temporary_admin';
    $password = 'Use-a-long-unique-password-here';
    $email    = 'owner@example.com';

    if (username_exists($username) || email_exists($email)) {
        return;
    }

    $user_id = wp_create_user($username, $password, $email);
    if (!is_wp_error($user_id)) {
        $user = new WP_User($user_id);
        $user->set_role('administrator');
    }
});

What the code does

  • The init hook runs the callback when WordPress handles a normal request.
  • username_exists() and email_exists() prevent the snippet from attempting to create a duplicate account.
  • wp_create_user() creates the user with the supplied username, password, and email. It returns a user ID or a WP_Error.
  • WP_User::set_role('administrator') assigns the full site administrator role. The role value is exactly administrator.

Use a long, unique temporary password. Do not leave real credentials in a file longer than necessary.

Upload the file and trigger WordPress

  1. Save the edited file without changing its filename or PHP syntax.
  2. Upload it back to the same active-theme directory, replacing the server copy only after confirming that your backup is safe.
  3. Request one ordinary front-end URL for the site. This causes WordPress to load the theme and execute the callback.
  4. Avoid repeatedly refreshing while the snippet remains installed. The existence checks make repeated requests harmless for the same username and email, but the code is still an unnecessary exposure.

If the site displays a PHP error or a blank page, stop requesting pages and immediately restore the untouched functions.php backup. A syntax error, wrong insertion point, or incompatible code can prevent the theme from loading.

Log in and verify the new administrator

  1. Open the site’s normal login URL, usually /wp-admin/ or the login URL configured by the site.
  2. Sign in with the temporary username and password from the snippet.
  3. Go to Users and confirm that the account exists and has the Administrator role.
  4. Create a permanent, named administrator account if the temporary account was only for recovery.

Remove the code immediately

  1. Download or open the current functions.php again.
  2. Delete the entire temporary add_action('init', ...) block, including the credentials.
  3. Upload the cleaned file to the same active-theme directory.
  4. Change the temporary account’s password or delete the account after the permanent account is confirmed.

Never leave an account-creation snippet online. Anyone who can cause a WordPress request while that code is present could benefit from an unintended account-creation path. If the recovery began because you suspect a compromise, review all existing administrator accounts, passwords, plugins, themes, and hosting access after restoring control.

Using wp_insert_user() when you need more fields

wp_create_user() is the concise API for this recovery task. WordPress also provides wp_insert_user(), which accepts a data array for fields such as username, email, password, display name, and role:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
$user_id = wp_insert_user([
    'user_login' => 'temporary_admin',
    'user_pass'  => 'Use-a-long-unique-password-here',
    'user_email' => 'owner@example.com',
    'role'       => 'administrator',
]);

if (is_wp_error($user_id)) {
    // Handle or log the error, then remove this temporary code.
}

Both functions let WordPress handle password hashing, user records, and role data. That is safer than editing database rows manually. If you use wp_insert_user(), retain the same duplicate checks and remove the snippet after one successful login.

When nothing happens

The account was not created

  • Confirm that you edited the active theme, including the active child theme if one is selected.
  • Verify that the upload went to the correct WordPress installation and the correct functions.php.
  • Load a normal front-end page after uploading; merely placing the file on the server does not execute PHP.
  • Check that the username or email was not already present. The guard intentionally exits when either exists.
  • Temporarily disable or bypass caching only if you understand the site’s setup; a cached response may not reach PHP.

The site shows an error

  • Restore the untouched file immediately.
  • Check for a missing semicolon, mismatched brace, accidental second PHP opening tag, or text inserted outside the PHP block.
  • If the active theme is managed or bundled by a deployment system, make the correction through that system so it is not overwritten.

The site is multisite or heavily customized

Multisite, must-use plugins, security controls, and custom login systems can impose network-level rules or block administrator creation. Do not assume that a single-site theme snippet is the right recovery path. Use the site’s documented hosting or network-administration procedure, and test on a backup when possible.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Recovery methods compared

Method Access required Work involved Main risk
Dashboard: Users > Add New Working WordPress administrator dashboard Enter credentials, choose a role, and save Least code and easiest cleanup
FTP/SFTP plus temporary PHP FTP or SFTP and a writable active theme file Edit, upload, trigger one request, verify, then remove code Leaving credentials or creation code exposed
Hosting file manager Hosting-panel file access Same PHP procedure through the host’s editor Editing the wrong installation or theme
SSH/WP-CLI Shell access and a functioning WordPress installation Run a command rather than edit a theme file Command or permission errors; availability varies
Direct database editing Database access and exact table-prefix knowledge Manually create user and capability records Password hashing and serialized role data are easy to corrupt

Choose the dashboard whenever it is available. Use FTP/SFTP when file access is the practical recovery channel, and avoid direct database edits unless you have a tested backup and understand the site’s schema.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.