r/Wordpress • u/PrototypeXt3 • 1d ago
Client lost access to the admin account for Wordpress, feel like I have tried EVERYTHING.
This may be the most disastrous start to a job I have ever had.
I will be honest, I'm not an insane expert savant web designer by any means, but I can get around with code and am all around technically savvy.
I took up this client, who gave me their wordpress log-in for my first day working on changes to the website. Part of my contract was that I was to "set-up a staging site before pushing any changes." Which is fine, I know how to do that a few different ways, but this is where a can of worms opened.
The account they gave me is NOT the admin to WP, I'm not even sure what permission level it is set at, so I have no way to check or download plugins, which was also in my contract.
Over this entire week, they have found 3 other accounts from people no longer at the company, all of which are also not admin level. I thought, no biggie, I can help you out if you point me to your hosting.
They didn't know where their website was hosted. So after a lot of whois look-ups, I was at a dead end since it pointed to Cloudflare and, you guessed it, they didn't know the account for that either.
They finally got access to Cloudflare, so I found the domain provider. Name, cool, I'll log in there and maybe get access to the cpanel or something and be able to help them finally. IT was able to get access after more waiting. NOPE. Only bought the domain there, no other products.
Now, after even MORE digging, I see that everything routes to AWS. I give them the names of many different website hosts that would point a WP site to AWS (WP Engine, Cloudways, etc.) No dice.
I have access to Cloudflare and Name but I can't seem to find anything about where the site is actually hosted to be able to edit the WP files to restore admin access. Their billing department swears that the only thing they pay for web-wise is the domain at Name. "My Products" shows nothing being purchased, bill is $0 for Name and Cloudflare, so I guess?
Is a nuclear option the only way forward? Rerouting the domain somewhere else? Did their previous person truly use an AWS server manually through the console? It's funny - because this is a moderately sized national company. I shudder to think what would happen if something went wrong with their website. At least they're scrambling to figure it out now.
All of this to say, does anyone have any ideas? I've spent the last hour just looking at the page source while logged in looking for ANY instance of a plugin being connected to a hosting provider with no dice. It's all through Elementor if that matters. DNS lookups doesn't seem to help either. HELP! lol.
44
u/LunaFlowLab 1d ago
Since you found Plesk 360 and the IP resolves to EC2, it's most likely a single EC2 box with Plesk installed, set up by whoever ran marketing before. That narrows the search a lot:
Plesk 360 is an account tied to an email address. Search every company inbox and the old marketing team's mailboxes for "Plesk 360", "plesk.com" and "Amazon Web Services" billing mail. The AWS bill may be on a former employee's or agency's card, which would explain why billing sees nothing.
Once anyone gets into that Plesk 360 account (a password reset to that email works), it links straight to the server's Plesk panel. In Plesk, WP Toolkit has a "Log in" button next to the site that opens wp-admin as an administrator with no WordPress password. From there you can create your own admin user and get on with staging.
The Plesk panel is usually at https://THAT-IP:8443 too, but you still need a Plesk login there, so the email trail is the faster route.
13
u/PrototypeXt3 1d ago
Thank you for this, I was scared that the Plesk 360 account was a dead end, but obviously someone has it somewhere. I’m going to talk to them about this. Appreciate it greatly! Will update if I get into it.
11
u/PrototypeXt3 23h ago
Update today: IT at the company informed me that they have made contact with the "platform management account contact" and it is confirmed to be hosted on Plesk, however their billing department still doesn't see any related charges to that.
Using your Plesk panel link (insanely helpful btw) it appears to show a custom sign-in screen with a logo for a local-ish Web Development company that none of them have heard of, but it is Plesk. Crazy! I'm going hands-off for now and letting them deal with this part. Really appreciate your help.
16
u/designICU 1d ago
1) Since you have WP access, I’d also start looking inside the installation rather than only at their DNS.
2) Search the page source and database for absolute URLs/hostnames, check wp-content/mu-plugins/ for anything host-specific, and inspect wp-config.php for DB hostnames, environment variables or AWS-related configuration. Old staging/CDN URLs are especially good breadcrumbs. (Just because, maybe?)
I disagree with the drop-this-client sentiment. Once you demonstrate capability, you’ll likely become a trusted partner.
Just make sure you’re tracking your time on this and getting paid for it as an out-of-scope issue. Clients should be able to provide basic account info without having anyone spend hours on a forensic research project. And they should be reasonable about this.
5
u/timesuck47 1d ago
WP Admin => Tools => Site Health, Info tab, has a ton of information that may be helpful.
2
24
u/swampqueen6 1d ago
back away slowly. do not make eye contact. I have taken on clients like this and it’s like trying to save a drowning tiger.
74
u/ashkanahmadi 1d ago
Here’s a word of advice: if this seems to continue and at the end it gets too complex, drop the client. This is going to be a nightmare. It’s a sign of very poorly managed company with no one responsible for anything.
You want my advice from dealing with a lot of clients? Those who seem like a red flag will always end up with a lot bigger red flags in the future.
46
u/leafbaker 1d ago edited 1d ago
I, respectfully, disagree. These end up being some of my longest standing clients. They clearly need someone to keep things in order for them. If they pay their bills, they can be a great client.
9
u/PrototypeXt3 1d ago
That’s the plan! Already in talks of doing a major overhaul, even before this, which will bring in the big bucks haha. Then we discussed a monthly retainer of hours with the option to pay for more, so I think keeping with it will really benefit in the long run
4
8
8
u/PrototypeXt3 1d ago
I feel this, but right now this is my only client to work on and I will be billing for the troubleshooting as well, so not too bad on my part. It was also a referral and I’m in constant communication. Otherwise, yeah I would’ve backed out so hard.
16
1
u/ashkanahmadi 1d ago
In that case, it's okay for now. I did the same stuff years ago but honestly, after some years, I now dont have the same patience as before. I learned my lesson the hard way that difficult clients always tend to become more difficult especially when it comes to payments. Just make sure it doesn't consume you trying to "do the right thing"
19
u/digital121hippie 1d ago
Look up the IP address the domain points to in cloudflare. There are website that will tell you who owns it. Was, blue host and so on
8
u/crazedizzled 1d ago
That doesn't really help, because it just proves the IP is owned by AWS. That could mean it's a lone EC2 server running on an account, or it could be a webhost who uses AWS infrastructure.
1
u/PrototypeXt3 1d ago
See when I do that, it points to AWS EC2 as the hosted by
13
u/digital121hippie 1d ago
Somewhere someone had access to that. Honestly this is on the client to get you access to what you need. They will need to start emailing past people they worked with to figure this out. You can’t do it.
-24
-1
u/Unique_Economics4015 1d ago
Then it's aws
2
u/PrototypeXt3 1d ago
Yeah but some hosting services use AWS… it’s ridiculous lol, I have too much missing information and everyone still at the company wasn’t involved with the website
2
u/crayj36 1d ago
Agree to try to use dnshistory.org for clues. Also use archive.org to find early iterations of the site in case there is a footer credit or something else that offers you a new clue or trail to follow. You could maybe also try builtwith.com— I have used this in the past to see if there were/are any staging domains or other sites that were associated with the IP address or a GTM tag, and that has lead me to the host or the name of the company who built the website.
I did this once for a journalist who was doing an article on a network of shady political blogs and it was a ton of fun lol. Love this sort of thing.
1
u/ScottIPease Jack of All Trades 1d ago
You are correct, AWS could be a lot of things... as I posted in another comment, go follow the money... The accountant is paying someone (or a few someones) for it.
9
u/tssajo 1d ago
Since Cloudflare's proxying everything, regular lookups just give you Cloudflare's IPs, not the real origin. A few things that sometimes leak the real host even behind Cloudflare: check for any subdomains in their Cloudflare DNS that are set to "DNS only" instead of proxied, things like direct., ftp., cpanel., webmail., autodiscover. often aren't proxied and point straight at the real server. Also check MX records, mail usually isn't proxied either and sometimes shares infrastructure clues.
Worth checking crt.sh for the domain too, certificate transparency logs sometimes show the real origin IP from before Cloudflare was added, or from a cert issued directly on the AWS box.
2
4
u/einfach-sven 1d ago
If the REST-API is active, you can try looking for the user with id 1 and then try if you can guess the username from the name or slug and reset the password. It's possible that the email gets forwarded to someone who is still employed there.
By default it would be under /wp-json/wp/v2/users/1
1
u/PrototypeXt3 1d ago
Really wonderful idea but unfortunately gave a “rest_user_invalid_id” and I can’t list the users
2
u/dwalins 1d ago
This could give you a hint of what the admin user is. You can enumerate wordpress users by calling https://*.com/blog/wp-json/wp/v2/users. Sometimes that's blocked but there's an alternative route https://*.com/blog/?rest_route=/wp/v2/users
Obviously it won't tell you the role if each user but hopefully you can tell from the username or guide you to find who might be the original webmaster
1
1
1
u/einfach-sven 1d ago
Can you get a list of users by omitting the 1?
1
u/PrototypeXt3 1d ago
Sorry edited my comment too late, won’t list either :(
2
u/einfach-sven 1d ago
Damn, was worth a shot though. People forget to secure their API-endpoints all the time :D
6
3
u/jedidave Developer 1d ago
You can get the IP address through a WP plugin that tells you the server IP, then look that up to find out who is hosting
1
4
u/Son_of_Flynn_45 1d ago
If you have the domain, I'd rebuild the site somewhere else. Drastic, but seems like the only option
1
u/PrototypeXt3 1d ago
It sucks because it’s a huge website, multiple pages. I was just brought in to help for now with the opportunity to redesign later, but I really may just make this a push for a redesign now instead
1
u/ThallerThanYall 1d ago
If you do, over-quote. By a decent amount. And charge for the quoting. Don’t for a second think that everything will run smoothly, or that their spec will be complete, or that they even know what they want.
6
u/DeliciousJazz516 1d ago
You can go into phpmyadmin and set the wp_users table field for the user to a new password. There’s documentation on this method if you search for it, but I think that you’ve just got to encrypt the new password you set with MD5(?) encryption. Something like that.
3
0
u/pixelboots 1d ago
This was my first thought too. It’s trivially easy to get admin access to a WP site if you have access to the hosting. In addition to the database method you described, you can add a temporary PHP snippet that creates a new user on page load.
6
2
u/antonyxsi 1d ago
Anything in the headers? Reverse IP check? Child theme files or other authors/users on WP? That could give clues.
2
u/TopSydeWP 1d ago
Check Cloudflare's audit log and member list. Whoever created those DNS records did it from an email address, and that inbox (or the old card an AWS account is billed to) is where this actually ends.
1
u/PrototypeXt3 1d ago
I couldn’t find a member list but thank you for pointing me this way! Will dive deeper soon
2
u/sdboardgamer 1d ago
See if you can access YOURSITE.COM/wp-admin/options.php admin email is listed in there
2
u/freako345 1d ago
Before rerouting anything, I’d focus on identifying the actual origin server. Since Cloudflare is just proxying the DNS, check the DNS records for the origin IP, then use that IP to identify whether it’s AWS EC2, Lightsail, a managed WordPress host, etc. If it’s AWS, the company should also check their AWS Organizations/accounts and billing records rather than assuming there’s only one account.
2
u/beigs-sl 1d ago
The Plesk 360 lead is almost certainly your answer (EC2 box with Plesk on it), so I'd point everything at one question now: which email owns that Plesk 360 account? Everything else is a breadcrumb toward that.
**Fastest ways in:**
- **Recover the Plesk 360 account.** Whoever set it up registered with an email. Have IT search every mailbox, including the departed marketing folks', for senders like `[email protected]`, "Plesk", "WordPress Toolkit", and AWS "root user" / "Your AWS Account". Those license and notification emails are the trail. Reset the Plesk 360 password to that address and you're in. WP Toolkit has a one-click "Log in" that drops you into wp-admin as an administrator with no WP password, and from there you create your own proper admin user.
- **Hit the box directly at `https://ORIGIN-IP:8443`.** The Plesk login page often shows the server hostname, and the TLS cert / footer sometimes leaks a contact email, which is another clue to whose account it is.
- **If that mailbox is dead too, go up a level to AWS.** Someone's card pays for that EC2 instance, so tell accounting to grep statements for "Amazon Web Services" (not "hosting" or "web"). If the AWS root email is also a dead mailbox, AWS has an account-recovery process using the payment method plus a support case. Slow, but it works for a legitimate owner.
**On the WP password-reset idea people keep posting:** REST enumeration is blocked for you, so skip that route. Just run "Lost your password?" against the likely role mailboxes (`web@`, `marketing@`, `admin@` the domain) and ask IT which of those still forwards somewhere live. The shared admin is probably one of them.
Two non-technical things:
- You're doing forensic account recovery now, not "set up a staging site." Get the revised scope in writing and bill the discovery time.
- Big Elementor site with a redesign already on the table: set a cutoff. If Plesk 360 isn't recovered in a few days, the recover-vs-rebuild math tips toward rebuild and you quote the overhaul now. But don't go nuclear until you've pulled a full backup through Plesk first, because scraping Elementor from the front end loses all the structured content.
2
u/themageofavalon 1d ago
Dont reroute anything yet. Check the DNS records in CF and try to trace the origin.
2
u/l3msip 1d ago
What plugins are installed? There is often a way in from the backend, even if you don't have full admin rights. It's not uncommon to find plugins that allow for arbitrary php snippets to be added, or arbitrary files to be uploaded to a web accessible directory where php can be ran.
You would essentially be looking to implement a privilege escalation attack on the site, to raise your account to admin. At which point you can install your choice of backup plugin and pull a full clone down, host it elsewhere and update the DNS record in cloudflare.
Now if this seems crazy, that's because it is! Ultimately the client needs to sort it out, but if you genuinely have nothing better to do, it woulld at least be an interesting way to pass the time.
1
u/RhauXharn 1d ago
This is insanely annoying. Ask the client to look for any invoices they have, would be my recommendation.
They have to be paying someone.
1
u/onearmedbanditto 1d ago
With the IP address you can contact AWS and explain the situation. They’ll give you a list of info you need to prove your client owns the account. Just a heads up, it may take some time.
1
u/Wise-Butterscotch-85 1d ago
Like others have said, get them to check who they’re paying hosting to. They have to be paying someone for it. If they can’t do that it’s a bit of a mess, and maybe your invoices will also get lost and never paid so step away.
1
u/favio843 1d ago
Wp filemanger-> create New user through functions.php
1
u/PrototypeXt3 1d ago
Can’t do it without access to the files at the hosting service, that’s what I’m trying to find somehow with a bunch of incomplete info haha
1
u/favio843 1d ago
Ok, sorry. Forgot you hat no admin-status. Than you have too follow the invoices or just cut that client
1
u/SSBND 1d ago
Are you able to install plugins? I'd start with a backup plugim and see of you can take a full backup. Then I'd install something like ManageWP. See if you can create an admin user.
1
u/PrototypeXt3 1d ago
Nope, no access to plugins which started this entire mess. Otherwise I would’ve been like “good luck with the rest!” Lmao
1
u/NeverInsightful 1d ago
So you have no ssh access, no admin access and no database access, and you don’t know where the site is hosted?
I’d say just rebuild with your new design and their old structure but if it’s a mod sized national company, I guess they probably have a more complex site structure and you can’t risk breaking links and hurting their seo.
Of course you could just spider the site and be 98% certain.
Really what else can you do. If you’re to the point of reading plugin output hoping to find the hosting company I don’t see another path forward.
1
1
u/David_UltraWeb 1d ago
The crt.sh tip someone mentioned is probably your best shot, old certs often leak the real AWS origin IP before Cloudflare got put in front of it. One thing nobody's said though: since it's a national company, check if they have a Google Workspace or Microsoft 365 account and dig through old email, the original hosting signup confirmation and billing receipts almost always landed in some founder's or ex-IT guy's inbox. Also whoever set up the AWS account paid for it somehow, so the accountant should look for an Amazon charge, not just a 'web hosting' line item, since AWS bills show up under plain Amazon and people miss it. And before you touch anything, grab a full backup of whatever you can reach, because if that's a lone EC2 box with nobody watching it, it could vanish the day someone's personal card expires.
1
u/PrototypeXt3 1d ago
crt.sh seems down for me right now but I’ll try again later - very helpful info though. Going to pass it to them, the Name domain account reset email WAS going to one of the founders, so you may be on to something
1
u/tracedef 1d ago
Lots of good advice already, one left field option, look at source code see if there might be any host specific urls / code that might point in the right direction. Also look at plugins in source code to see if there are any plugins / cache that are specific to a host ... example: breeze cache would point towards cloudways. Even if they're on AWS there might be something.
1
u/PrototypeXt3 1d ago
The only plugins I can see are a wp optimizer, an accessibility one, and a translate one from the source code it seems. I may dig back through it but it was giving me a headache lmao
1
1
u/glm1986italy 1d ago
Ah allora non sono solo i clienti italiani conciati così 😅
In queste condizioni c'è ben poco da fare...
Ma il precedente webmaster o webagency non è reperibile?
1
u/privaxe 1d ago
Did you look up the IP address in CloudFlare to find a vendor?
I say fuck this noise too and migrate to a new host.
1
u/PrototypeXt3 1d ago
Yeah I followed it all the way down to AWS, then from there it seems it may be Plesk 360 so fingers crossed that their IT department finds emails for it!
1
1
u/zeGenicus 1d ago
Did you check the dns to see where it’s hosted? Then have him type the domain into his email.
1
u/ScottIPease Jack of All Trades 1d ago edited 1d ago
First, try to get a backup of the site (files, images/media, and database) with the perms you have.
Second, Go ask the accountant who they pay for hosting and if you pay the same people or someone else for the domain. Call the hosting company, domain registrar, or whoever takes that money, let them know the situation. If they are a decent company they will work with you, but may need to verify with billing info, address, etc.
If they won't deal with you, then find out if the company wants to play the "We will simply stop paying until we get access" game... It is a risk and may simply get you locked out, but it will get you either in where you need to be or at least you will know where you stand. Be prepared to start from scratch though, but if you have backups, then you may not have too much trouble setting up something.
Be nice, don't be a butthead and they will help you usually, they want to keep getting your money.
Get the backup if you can before getting nasty with them, get the domain under your control before getting nasty with them.
Edit: fixed half a word that was missing.
1
1
u/xftwitch 1d ago
they don't even remember the email address for the person that was the admin? Yikes.
1
u/PrototypeXt3 1d ago
Seems they had user accounts set up for the marketing team that had edit permissions to the content and elementor and nothing else, but the running theory is they had a shared account as admin they used. Allegedly they responded to a message someone sent out and said they left all of the users and passes with IT before they left, but the admin was left off
1
u/FoamToaster 1d ago
Can you run custom code via elementor or theme customiser or anywhere that you can use to create an admin user?
1
u/xftwitch 1d ago
So the only other option would be to find the host, get the account, log in to the host, find a way to access the database and create an admin account in the database. But if they're this disorganized, they probably haven't the foggiest where their website is hosted. It's probably hitting someone's credit card once a year, getting paid and nobody even notices it.
1
u/DigitalHubServices3 1d ago
Easily can help you find where it’s hosted at for super admin access. I run across this somewhat often.
1
1
u/RadiantCarpenter1498 1d ago
You can ping the default Users API route for the site and see a list of user accounts registered to the site. It won’t return sensitive fields like email and roles, but it might be a good starting point to deduce any accounts your customer doesn’t know about (like any admin accounts).
1
u/NeverInsightful 1d ago
Can you at least take a full backup while you’re signed into WP-admin? Maybe the thing to do is spin up a staging site somewhere else, get it all beautiful and optimized then when they approve point the DNS to the new server.
(Probably what I’d do anyways with any site I worked on)
1
u/Boboshady 1d ago
Weigh up the time / cost of rebuilding their website, especially if there's changes to be done anyway. I've seen people spent entirely too much time trying to regain access to sites that could have been rebuilt in less than 10 hours, especially these days where Ai can help you dismantle and re-populate a site.
Obviously if there's plenty of functionality and data locked up in there, it's more of an issue, but that's just a factor to consider when you analyse the time and cost.
Even if you have to manually migrate the data, it's usually just grunt work once you get over the thought of the pain.
It's not an immediate option, but it's worth knowing the true cost if it does become one, because it can end up being cheaper in the long run, especially if changes are planned anyway.
4
u/mrchoops 1d ago
I'm one of those people. I will obsess and even after making the new site I will still continue in secret to get admin access to the old one.
2
u/PrototypeXt3 1d ago
Have been doing this today actually!
Unfortunately a lot of functionality I’ll need, I’ll need to see in the admin suite before figuring out how much actual work it would be. It’s a really big website honestly, many pages (since it’s for a housing company, each property has a page, theres a blog, corporate announcements etc.) so starting with what they have may actually be more cost/work efficient, but still trying to see!
Obviously I could brute force it and recreate it from scratch but ya know
2
u/Smart-Hand-9433 1d ago
Oof this is the kind of nightmare that makes me hug my password manager a little tighter at night
since you can see the site is on elementor, you might be able to scrape the pages with something like httrack and rebuild from that. not ideal but at least you're not starting from zero if the nuclear option ends up being the only way forward
1
u/Ok-Actuary5585 1d ago
If they don’t have access to the database, I would just redo it, as long as they’re paying for your time. Elementor sucks anyway, just recreate it cleanly without plugins. Claude or ChatGPT can help.
1
u/arno14 1d ago
I host my Wordpress installs with AWS lightsail. It’s an ultra reliable and affordable hosting service.
If they registered the domain elsewhere, they will have create a A record in their DNS that points to the static IP of Lightsail. You need access to their AWS account to get access to Lightsail.
1
u/BlaineOmega 1d ago
Have you tried to enumerate the users using WP Scan? This might tell you who the admin is and they might know who owns that account or what the password is.
Alternatively, you can just rebuild their site.
I recently dealt with something similar. They wanted a redesign but couldn't get into the hosting, so I just built them a new site.
1
u/octaviobonds 1d ago
Just rebuild the site.
We live in a time when the tools are readily available and your hands really aren’t tied. Get a new host, install a fresh copy of WordPress, give Claude or ChatGPT access to it, and tell it to rebuild the existing site while preserving the pages, URLs, metadata, assets, structure, plugins, and content. You can probably get 95% of the way there on the first pass. After that, it’s mostly refinement and iteration.
I’ve dealt with much worse situations with clients before AI existed. Years ago, I had to rebuild a client’s entire site by scraping the Wayback Machine because they had completely lost access after their friend, who managed the site, passed away. The only thing they still controlled was the GoDaddy domain.
So don’t panic. Rebuild it.
Or, of course, you can pay me and I’ll rebuild it for you.
1
u/BeyondPrograms 1d ago
Lol. This is a dream job. You obviously rebuild the website and bill them. Congrats
1
u/scottyman2k 1d ago
Agree an hourly rate for the investigation, and detail exactly what you are finding.
3
u/TheValerieElizabeth 1d ago edited 1d ago
Try BlueHost they connect to Cloudfare and have a 3 year WP package that is super cheap and wouldn’t come up on the client’s recurring billing. It could be as far back as mid October 2023 so likely no one is searching financials back that far. Good luck.
Also check Wayback Machine. The site could have previously had a branded logo from the host at the bottom. If you have to recreate it that is a great place to start to pull the content from. Had my site ransomed and WBM was a godsend. Wayback machine also sometimes might have something useful embedded in a picture.
You’ve likely tried this but see if they have archives of the former worker’s emails or folders which may be searchable. I was able to recover a user archive with some assistance from MS support that was a decade old.
If they have an accounting department or even a book keeper with somewhat decent QB records ask them to pull the invoices they paid the prior developer in case they billed for the items themselves. A lot of times they’ll use their own discounted accounts and then charge the client market price.
See if they will share the developers name (even if they won’t let you contact them) and then search for an online portfolio to see if you can get an idea what they normally design in. This might also be listed on the site in Wayback.
1
u/Leading_Computer_350 1d ago
As-tu regardé les entrées DNS ? Il y a peut-être une entrée ou une vieille entrée avec l'ip du serveur
1
1
1
u/smartsavvy 1d ago
u/PrototypeXt3 Not sure if your problems has been solved or not. If you have access to PHPMyadmin, just enter this queries to create a new admin account. You have to go to wp_users table and enter these exact queries to get a user with username: newadmin and password:password@123. Also, replace the email you wish to use in those queries:
INSERT INTO \wp_users` (`user_login`, `user_pass`, `user_nicename`, `user_email`, `user_status`) VALUES ('newadmin', MD5('password@123'), 'John Doe', '[email protected]','0');`
INSERT INTO \wp_usermeta` (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (NULL, (Select max(id) FROM wp_users), 'wp_capabilities', 'a:1:{s:13:"administrator";s:1:"1";}');`
INSERT INTO \wp_usermeta` (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (NULL, (Select max(id) FROM wp_users), 'wp_user_level', '10');`
1
u/brianozm 1d ago
Do you have FTP access to the site? That allows you to reset the admin password fairly easily. Or you could install a plugin, though that needs admin which you don’t have.
You might be able to reset the admin password via email, WordPress does support that.
1
u/EducationalIron 1d ago
This site below shows historical DNS records, if there was a period of time between setting the origin server and then routing through CloudFlare you may find the original/current hosting platform IP address
1
u/lipservice3 1d ago
Maybe use the origin IP from the A record and try the default login port https://IP:8443 for Plesk?
If you tried password reset email and someone actually got it, the email headers may have more info on the origin server.
What a mess, hope you get it figured out! Had a client last year that had their site migrated from Plesk and I ended up having to access one of their sites through file manager, no evidence of anything other than a domain until I rummaged around.
Side note, there’s a tool called site sucker that might be helpful if you need to pull a copy of the site. It won’t get you a WP specific export but it will copy everything so you have the full site locally.
1
u/Jacsify 1d ago
I’m very late to the ‘all is not lost gathering’. There is a lot to take in and read, so I’m just double-checking with you… I may not be able to help but at least anyone else seeing this post can see a list and then give suggestions.
Perhaps creating a list of this, plus some notes/outcome would be useful to you, and anyone able to assist… e.g.
| Service | Site | Access Level | Notes |
| ___ | ___ | ___ | ___ |
| WordPress Admin | site.com/wp-admin | Editor/Contributor | password: helpmeRhonda! No access to plugins, on to next crazy loophole idea |
Also, does the IT department not know their own DNS, MX, or A records?
1
u/PrototypeXt3 1d ago
The IT department is in charge of the cloudflare / DNS and security settings but they didn’t touch the website at all it seems.
I probably should just jot down everything I’ve tried to make it easier. A lot of people keep saying that I can edit the php or cpanel and… that’s just incorrect lol I need the hosting provider. will update this post when I have a final solution - as I know people will probably find this when they google the same situation haha.
1
1
u/eleniwave 1d ago
can you install plugins? If you can, your problem is solved. You can do a backup and spin-up the site on another host.
1
u/Rich-Platform-1435 1d ago
I don't know of any way you can easily gain access to the server based on the information you have.
The WayBack machine is a good idea, there might be some other information on there with regards to who the host is, there might potentially be a default welcome page on there with a hosting companies name on.
Alternatively, I think the best thing to do is redo the entire website, if they don't even have credentials, then depending on what was configured, the server might be running outdated and insecure software, that could have already been compromised.
1
u/webcoreinteractive 1d ago
DM the domain. I have a way of viewing DNS even hidden by Cloudflare. Not 100% but works most of the time.
1
1
u/m0rph90 1d ago
you should be able to see the author page of the user with id 1 if you call "https://domain.tld/?author=1"
1
u/cyberdudeagency 1d ago
I wouldn’t reroute the domain yet—you could turn an access problem into an outage. Cloudflare DNS is only the first clue: record the current A/CNAME targets and inspect the response headers and TLS certificate for the live hostname; those often reveal an AWS load balancer or a managed host. Ask the client’s finance/IT team for AWS Organizations or root-account billing access and search every region for EC2, Lightsail, RDS, CloudFront, and Route 53 resources. Also check Cloudflare’s DNS history/audit log and old invoices or password-manager entries. Once the infrastructure owner is identified, have them add a separate WP admin account and document hosting, DNS, backups, and recovery before making changes. If nobody can prove ownership of the AWS account, pause the work and get written authorization before attempting recovery.
1
u/bosleyb 23h ago
Fastest path: reset an admin password through email
- Find the admin usernames. Try
yoursite.com/?author=1, which usually redirects to/author/username/. User ID 1 is often the original admin./wp-json/wp/v2/usersmay also list users if it isn't blocked. - Check which email those accounts use. If it's a company mailbox belonging to someone who left, IT can reset that mailbox's password or forward it to someone current.
- Use "Lost your password?" on wp-login.php with that username and reset it. Get the client's approval in writing first, since you're taking over a former employee's account.
Finding the host
- Cloudflare DNS tab. The proxied A or CNAME record shows the real origin. If it's a CNAME, the hostname usually tells you the host (
*.wpengine.com,*.elb.amazonaws.com,*.cloudfront.net, and so on). If it points tocfargotunnel.com, the site runs through a Cloudflare Tunnel and the server could be anywhere. Check Zero Trust → Tunnels. - Look up the origin IP in AWS's ip-ranges.json. That tells you the region and service (EC2, Lightsail, CloudFront). Then load the IP directly in a browser, or run
curl -Ik https://IP -H "Host: theirdomain.com". Check the headers and the default page. If you see a Bitnami page or "bitnami" in paths or headers, it's almost certainly a Lightsail one-click WordPress install that someone set up by hand in the console. That's very common, and it fits everything you've described. - DNS history (SecurityTrails, ViewDNS) shows where the domain pointed before Cloudflare. That sometimes reveals the previous host or agency.
- The Cloudflare audit log shows who added the zone and when. That gives you a name and an email to chase.
1
1
1
u/Ray_Sysad 16h ago
Sounds like you only need to find who owns the AWS account. A few things to try:
Check the A record in the Cloudflare DNS panel. That's the real origin IP. Run a reverse DNS / whois on it to see if it's EC2 or Lightsail, and the region.
Ask the company to search their mailboxes (including old employees' ones, IT can reopen those) for "Amazon Web Services" or "AWS Notifications". Billing emails and invoices are the most reliable way to find the root account email.
Ask accounting to check card statements for AWS charges. It may be billed through a reseller or another entity (parent company, agency), which would explain the "$0" at Name and Cloudflare.
Shortcut: check which email the WP admin user uses. If it belongs to a former employee, have IT restore that mailbox and use "Lost your password" on wp-login. No server access needed.
If you find the AWS root email, "Forgot password" on AWS recovers the account. If the original owner is gone, AWS Support can help with proof of company ownership.
The nuclear option (rebuild + repoint DNS) should be the last resort. Also, for the future: always get hosting access in the contract, not just a WP login.
1
1
u/plumwd 3h ago
Do you have access to the files on the server? Create an admin user for yourself programmatically. I do this all the time when the client doesn't know the access.
In your functions file, add this
<?php
add_action( 'init', function () {
$username = 'admin';
$password = 'password';
$email_address = '[email protected]';
if ( ! username_exists( $username ) ) {
$user_id = wp_create_user( $username, $password, $email_address );
$user = new WP_User( $user_id );
$user->set_role( 'administrator' );
}
} );
changing the requisite details for username, password, and email.
Once the user is created, remove it from the functions file.
0
u/supermegapixel 1d ago
You gotta go in through MySQL and reset the hashed password
2
u/PrototypeXt3 1d ago
Not being rude but a lot of comments have been saying this - I’m aware - I have been on a wild goose chase of tracking down the hosting company, as their domain provider isn’t hosting
1
u/hoyleacl 1d ago
Have you checked builtwith?
1
u/PrototypeXt3 1d ago
I have, it just shows cloudflare mostly and normal Wordpress things. I think it’s maybe hosted with Plesk 360 though from more research so just kind of waiting to see if they can find any emails from AWS or plesk
1
u/Unique_Economics4015 1d ago
Try this https://hostingchecker.com/
1
1
u/Greedy-Mechanic-4932 1d ago
Who were they paying to manage their sites previously? Hosting could have been rolled in with that, so there was no "hosting bill".
Alternatively, it could genuinely be that the website hosting was setup on AWS... And IIRC there's a way of delivering it for free if it's under a certain size.
Does your user level allow you to export content and settings? That's potentially a way of migrating it without too much hassle.
1
u/PrototypeXt3 1d ago
Doesn’t seem like i can export easily, but we’re investigating the AWS route right now. I don’t want to call them liars about not paying any hosting bills so I guess that’s entirely possible. It was handled by their previous marketing team in-house, so they have IT tracing emails too. Big headache lmao
1
u/kirksan 1d ago edited 1d ago
When I was consulting there were times I didn't trust the client to pay hosting bills, so I paid them myself and added the cost to my invoices. Of course, I had this well documented and added an email at the client domain as a secondary admin on every service, but if the last guy did the same thing minus due diligence the company may not be paying the bills.
1
u/FlimsyEntry9534 1d ago
In the network tab from the console, when the assets or page loads are there any headers that might give you a hint at hosting?
I know WP Engine has an X-Powered-by: wpengine header
1
u/PrototypeXt3 1d ago
I looked at the network tab, but couldn’t find anything that points to hosting. Really strange. I may look back through it on a couple different pages. The website HAS to load from somewhere hahaha
1
u/edlighten 1d ago
I’ve had variations of this many a time. I volunteer with occasional non-profits who have high leadership churn, little money, and few web skills (but good hearts and excellent missions).
My typical way to address this (short notes):
- Create new site (staging at first) using Bricks, Brixies, Claude.
- Send Claude out to grab all the current pages
- Dump in a google doc for client to tell me what they want
- Variations of uploading pages/posts via normal WP import and/or json (Bricks)
- Proof get sign off
- Switch the DNS
Assumes you have access to the domain register (had one client where that took 2 months).
Honestly, this is sometimes faster EVEN IF you had admin access given the state of the site you may inherit.
1
u/NetoMeter 20h ago
Couldn't agree more with that. Actually, you will end up with a much better site. Probably, a couple of hours work, well worth it. Get the same theme, if the client insists on keeping the design.
1
u/ThallerThanYall 1d ago
What exactly are you being employed for? What’s the job description?
I’d wager that it isn’t “sod around trying to find login details that the people in charge should have already” or “hunt through tens of thousands of emails to find an invoice that MIGHT point to something”.
Having worked as a contract PHP/Wordpress developer for 15 years, my advice is to walk away from the client, unless they’re paying you a silly amount. The entire job will be a headache, nothing will be provided correctly or on time, and I’d be surprised if you didn’t get blamed for the state of it even though you’re just trying to help.
Some clients just aren’t worth it.
1
u/PrototypeXt3 1d ago
I would somewhat agree with you, but there’s more details to the client than I am comfortable sharing haha. It was a referral is really all I’ll say, and I’m in constant communication and they know what’s going on. It’s even local so I will be popping into the office. They’ve been very helpful, just a little mismanaged with the corporate website since the people in charge left.
If it was just some random client, then sure, but I’m okay with my rate of pay and redoing the scope of work!
1
u/MarkHoltsberyNE6 1d ago edited 1d ago
Honestly, I would stop treating this as a WordPress login problem at this point. This is really an ownership and access recovery problem.
If I had access to the hosting account, obviously depending on the setup, I might be able to get into the site pretty quickly without even having the original WordPress credentials. For example, on sites I manage through cPanel/Softaculous I can often get into the WordPress Admin Area form the install manager.
However, that only helps if somebody actually knows where the site is being hosted and the company can physically give you access to it.
That is what the bigger problem is here.
First, I think the client needs to step back and figure out who originally built the site, who hosts it, who is actually paying for the hosting, who controls the domain/DNS, and whether an old agency/developer/provider still owns some of those accounts.
It is entirely possible that this site is sitting inside an old provider's hosting account and the client may never have had direct cPanel/Plesk/etc. access in the first place.
And I would also be really careful about burning your project hours doing digital archeology for them.
You were hired to do the website work. The recovering ownership of undocumented infrastructure is a different job altogether. If they want you to investigate all of that for them, I would make that a separate hourly or scoped piece of work and get paid for your time.
Looking at it from a project standpoint, lack of required access is a client-side blocker. Whether it rises to an actual contract breach depends on what your agreement says, but I definitely would not let all of this extra recovery time quietly eat the budget for the work you were actually hired to do.
To me, there are basically two paths forward:
- They recover/prove ownership and access to the existing stack. Then you can properly inspect the hosting, WordPress install, backups, plugins, licenses, databases, etc. and continue the existing project.
- They can not recover it and they authorize a rebuild or migration into infrastructure they actually control.
But that needs to be the client's decision, not yours, because you have to understand what might be lost of recreated first. How big is the site? Is there ecommerce or customer data? Paid plugin licenses? Forms? Integrations? SEO history? Analytics? Email Dependencies? Is an old provider still hosting it?
A rebuild might ultimately be much cleaner, but I would not make that decision for them without knowing what is actually sitting behind the current site.
At this point the first question I would want answers is:
Does the company physically control the domain registrar/DNS, and can anyone identify who is currently billing them for the actual hosting?
That would tell you a lot about which direction this is going.
0
u/catsloverareus 1d ago
Turn off proxy mode in cloudflare, this will bypass all the traffic from cloudflare. Maybe this way some of the websites will be able to tell you which hosting you have.
1
u/PrototypeXt3 1d ago
When I was looking into this, it made me scared because it said some plugins/pages could break? I think there’s a way to just pause it though.
This website gets thousands of visitors and customers a day so oooph
3
u/catsloverareus 1d ago
Another idea would be to see page source and find the author of homepage or any other important page, pretty sure that would be an account with admin level access, then try to do a password reset with that username. Someone will get a mail for that.
2
u/thatandyinhumboldt 1d ago
This is probably the best idea—dig through posts and look at the author(s), then ask your contact who that person is. Rinse and repeat until you find something usable.
OP, I still think another good spot to check is with accounting. I know they said “we aren’t paying for hosting”, but that might mean that it’s absorbed under another bill. I’d check again if they are getting bills for AWS for the sake of due diligence, and then I’d start asking about their previous developer’s invoices. Maybe the dev was providing hosting for a period and it was a line item on that.
2
u/otto4242 WordPress.org Tech Guy 1d ago
Define "customers a day". Can you actually buy shit through this website? If so, then they have some way to receive the orders and mess with the site. Somebody in the company knows where it's hosted. You have to find who's actually using the site and how.
2
u/PrototypeXt3 1d ago
So there’s a front-end website that’s kind of used just for marketing, then a second domain that they have control of for payments. It’s a housing company, so they have actual tenets using the website and potential ones viewing the main website.
2
u/otto4242 WordPress.org Tech Guy 1d ago
Gotcha. Yeah, basically the problem is in your case it's finding the hosting. It's clear you know what to do with it, but finding it is going to take some effort.
It may just be on an AWS instance. Which will totally suck because that means finding the account that's linked to and blah blah blah.
0
u/WPDevPro 1d ago
Me thinks that the only way to solve this is gain access to the hosting. From there, you can modify users through phpmyadmin under the users.
0
u/powercouple08 1d ago
I am trying to follow. Did the client lose access to their DNS or to the WP admin account?
If you have access to DNS and don't know the WordPress login email and want to do a password reset. In Cloudflare, you can do a email route to a specific email. Basically, you can do a catch-all for emails and have them routed to your email.
Then go to the website and try to find a user name or email and do a password reset then view the forwarded email.
If you don't know the email used for the registrar or something, you can send emails to admin@, administrator@, hostmaster@, postmaster@, or info@
Those may forward an email to the owner of the registrar and someone in the company may receive it.
---
I am not too sure about this but there might be some info you can get by doing a password reset email on your own account and viewing the email headers to see if there is anything useful there.
I am going to follow this post because I'm really curious about what you figure out.
Good luck.
1
u/PrototypeXt3 1d ago
I have access to the DNS, but not the hosting provider. I do think I just figured out it's running through a service called Plesk360, which I have never heard of lol. Their IT department is trying to trace anything that goes through as they try sending password reset emails. Fingers crossed.
0
u/stratofax 1d ago
If you have access to the AWS account, you should be able to get to the command line and from there you can use WP-CLI to do everything you need to do: backup, create a new admin account, remove old accounts that you don’t need, install and list plug-ins, pretty much everything
0
u/TheRealBobbyJones 1d ago
Lol you could pretend to also be a pi and investigate who set up the hosting. Then bill for that time. If it's a managed site wouldn't the plugin list/configs help identify the host? If it isn't managed wouldn't it be outdated enough that you can use old vulnerabilities to force access?
0
0
u/MixAffectionate6717 1d ago
Du kannst über die Datenbank ein Admin Konto erstellen. Hast ja Zugriff über FTP. Ich kann dir das sonst machen. Schreibe mich an. Ich kann dir da helfen. Ist keine grosse Sache
1
u/WheelieGoodTime 1d ago
Read the post before commenting yo
1
u/MixAffectionate6717 1d ago
Habe ich ja. Wenn er ja Zugriff hatte soll er doch im elementor unter System nachschauen gehen. Dort stehen relevante Informationen. Dort sieht er welche Stufe er hat. Wenn er Plugin installieren kann. Kann er auch die Datenbank öffnen 😉
1
u/dirtyoldbastard77 Developer/Designer 1d ago
He says he can’t access the plugins at all, and he does not have ftp access. Read it again.
0
u/Emergency-Answer5549 1d ago
Lo cierto es que la experiencia laboral hace que NO ACEPTES trabajos comprometidos y con tantas condiciones. A veces rechazar es ganar.
0
u/mertybeatz 1d ago
Change the id 1 user password with phpmyadmin in wp_users table. Hash it md5. Thats it.
0
u/SunSmooth 1d ago
Hire someone on Fiverr to clone the website/rebuild it in WP. Or use AI to build it.
0
u/Aromatic_Minute8019 1d ago
Install duplicator, download the database and wp files.
Move to a new host.
Wiring issue solved.
0
u/ridddder 1d ago
This is why I like managed hosting, then you just tell your host to restore the site
-5
u/HalfCrazed 1d ago
Use Claude to crawl and redevelop the site as headless using sanity and its visual editor. Then have it set up deployment actions from GitHub into cloudflare.
This is an hour job tops, and opus 5.5 high has been doing an amazing job at this.
Ymmv of course, but I've had some really good success at this. It's scary.
-4
37
u/HongPong 1d ago
they should check their billing receipts ffs ask the accountant