Skip to main content

CreateWeb

WordPress User Roles: Security and Access Management (2026)

July 8, 2026

Blurred blue curved shape on a white background.
Person editing WordPress user roles and permissions on a laptop at a desk with books, a notebook and coffee.
Soft turquoise curved blur on a white background.

WordPress powers over 43 % of all websites on the internet. That popularity also makes it a prime target for attacks: in 2025, 11,334 new vulnerabilities were recorded in the WordPress ecosystem, an increase of 42 % over 2024 (Patchstack, State of WordPress Security 2026). A significant share of these vulnerabilities relate to privilege escalation, attacks in which a user with low permissions gains administrator access. In early 2026 alone, Wordfence reported a vulnerability that affected 100,000 sites through a custom fields plugin.

Behind these numbers lies a simple truth: the way you configure user roles in WordPress directly determines how secure your site is. This article from the CreateWeb team is a complete guide for anyone who manages a WordPress site, from the owner of a company website to the administrator of an online store. We will also introduce the WordPress Access Control Pyramid, a 4-level framework that organises access management from role architecture through to monitoring. If you would rather have a team take care of it, see our WordPress site maintenance.


What are user roles in WordPress

A man presents “User roles in WordPress” and cybersecurity data to six colleagues in a modern office.

WordPress uses a system of roles and capabilities to control what each user can and cannot do. A role is a collection of capabilities, and each capability represents a specific action, for example edit_posts, publish_pages, install_plugins or manage_options.

This system was designed with flexibility in mind. The administrator of a corporate website can define exactly which team members have access to which features, without granting unnecessary permissions and without restricting the workflow.

Understanding this architecture is not a technical curiosity; it is the foundation of security. If every user has more permissions than they need, every compromised password or vulnerable plugin becomes a direct path to full control of the site.


WordPress Access Control Pyramid: a framework for access management

One of the most common mistakes in managing WordPress access is focusing on a single aspect (“I’ve enabled 2FA, so I’m protected”) while every user has the Administrator role. Real access control is multi-layered and starts with the right role architecture. This framework, which we call the WordPress Access Control Pyramid, organises management into 4 levels, each built on the one before.

LevelWhat it coversWhy it sits here
Level 1 (base) – Role Architecture6 built-in roles, capabilities, custom rolesWithout understanding the roles, everything else is futile
Level 2 – Role AssignmentPoLP, the right role for each taskAssigning roles wrongly is an attack vector
Level 3 – Account Protection2FA, passwords, login limits, login URLProtects the accounts themselves from compromise
Level 4 (top) – Monitoring & AuditActivity Log, quarterly audit, escalation protectionCatches what the lower layers miss

The principle of the pyramid: you start from the base (Role Architecture). You cannot apply the principle of least privilege (Level 2) if you do not understand what each role does (Level 1). Account Protection (Level 3) protects correctly assigned roles, and Monitoring (Level 4) catches anomalies. Skipping the base makes the upper levels meaningless: perfect 2FA on an account with unnecessary Administrator rights still hands over full control if it is compromised.

Applying the framework: you build from the bottom up. First you understand the roles, then you assign them correctly (PoLP), then you protect the accounts (2FA), and finally you monitor activity (Activity Log). Each level reduces the attack surface.


Level 1 – Role Architecture: the six built-in roles

Five specialists analyse charts and data while managing user roles in WordPress in an elegant, modern office.

WordPress offers six standard roles, each designed for a specific type of user. Understanding the differences between them is the first step towards managing access properly.

Administrator is the role with full control. An administrator can install and delete plugins and themes, edit PHP code, manage users (including other administrators), change site settings and delete all content. On a standard (non-Multisite) installation, this is the highest role. That is exactly why the number of users with this role should be kept to a minimum: one, two at most.

Editor manages all of the site’s content. Editors can create, edit, publish and delete pages and posts, including other people’s. They can moderate comments and manage categories and tags. The important limitation is that an Editor has no access to site settings, plugins, themes or users. This role is ideal for a blog’s editor-in-chief or a content manager.

Author can write, upload media files, and edit and publish their own posts. Authors have no access to other people’s content and cannot publish pages. A suitable role for bloggers and copywriters who work independently.

Contributor can write and edit their own drafts but cannot publish them; that requires approval from an Editor or Administrator. Contributors cannot upload files. This role suits guest authors and new team members who have not yet been given full trust.

Subscriber has minimal access: subscribers can log in to the admin panel, read content and edit their own profile. Nothing more. This is the default role for registered users of the site.

Super Admin exists only on Multisite installations. This role has control over the entire network of sites: it can create and delete sites, install plugins and themes at network level and manage all users. On Multisite, the standard Administrator is restricted and cannot, for example, install plugins unless the Super Admin allows it.

WooCommerce roles: Shop Manager and Customer

When you install WooCommerce for an online store, the platform automatically adds two extra roles designed for the needs of e-commerce.

Shop Manager is perhaps the best-balanced role in the entire WordPress ecosystem. It provides full access to products (create, edit, delete), orders (view, process, refund), coupons, reports and WooCommerce settings. At the same time, a Shop Manager cannot install plugins, edit code, change the theme or touch server settings. This means you can hire an operations manager for the store and give them full control over day-to-day operations without risking the technical integrity of the site.

Customer is the role every customer who registers in the store receives. It allows them to view their own orders, manage addresses and edit their profile. There is no access to the admin panel beyond this basic functionality.

These roles are an important reason why WooCommerce is the preferred solution for online stores in Bulgaria: separating operational management from technical administration is critical for security in stores that process payments and personal data.

When the standard roles are not enough

The six built-in roles cover the typical scenarios, but real business needs often call for finer tuning. Here are a few examples from our practice.

A marketing manager who needs to edit pages and publish blog articles but should not have access to comments or users. The standard Editor role gives too much, and Author too little. An intern who needs to upload media files (Author can, Contributor cannot) but should not publish without approval (Author can, which is a problem). A multilingual editor who manages only the Bulgarian version of the site. An online store’s accountant who needs to see WooCommerce reports but should not be able to edit products or orders.

In each of these cases, the solution is to create a custom role with a precisely defined set of capabilities.


Level 2 – Role Assignment: the principle of least privilege

The Principle of Least Privilege (PoLP) is a fundamental principle of information security: each user receives the minimum set of permissions needed to carry out their tasks. No more, no less.

In practice, this means the following. The copywriter who writes blog articles gets the Author role, not Editor. A freelancer who publishes a guest article once a month gets Contributor. The SEO specialist who optimises meta tags and titles gets Editor. The online store manager gets Shop Manager. And the Administrator role stays reserved for the site owner and the technical administrator.

Why does this matter so much? Because every account with excessive privileges is an attack vector. If the copywriter has the Administrator role and their password is compromised (through phishing, a reused password or brute force), the hacker gains not access to drafts but full control of the entire site. They can install a malicious plugin, change the code, steal data or delete everything.

Melapress data from 2025 shows that 96 % of surveyed WordPress administrators have experienced at least one security incident, and 64 % have suffered a full breach. Correct role configuration does not eliminate every risk, but it drastically reduces the attack surface. This ties directly to protection through security plugins, which we cover in a separate guide.

Plugins for managing user roles

Two plugins dominate the market for managing roles and capabilities in WordPress, both with free versions that are sufficient for most scenarios.

User Role Editor is the most popular plugin, with over 2 million active installations (WordPress.org). It offers a visual interface in which you see all the capabilities of each role as checkboxes and tick or untick permissions with a single click. It lets you create entirely new roles, clone existing ones and add capabilities to specific users. The free version covers most needs, and the Pro version adds control over access to admin menus and widgets.

PublishPress Capabilities (formerly Capability Manager Enhanced) offers similar functionality with a slightly different approach. Its strength is detailed control over content types: you can configure different permissions for posts, pages and custom post types separately. The Pro version adds Admin Menu access control and integration with WooCommerce capabilities.

Both plugins are compatible with WooCommerce and with multilingual plugins, which makes them suitable for complex projects. Choosing between them is a matter of preference. When choosing them, we apply the same criteria as for any plugin, as described in our central article on WordPress plugins.

It is important to stress that a role management plugin should be installed by an Administrator, and changes should be tested in a staging environment before being applied to the live site. A wrong change to capabilities can lock users (including you) out of features they need.


Level 3 – Account Protection: protecting the accounts

Configuring roles correctly is only half of the equation. The other half is protecting the accounts themselves. Here are the specific measures, in order of priority.

Two-factor authentication (2FA) is the single most effective measure for protecting accounts. Even if the password is compromised, a hacker cannot log in without the second factor (usually a code from a mobile app). Plugins such as Wordfence and WP 2FA offer free 2FA functionality. Make 2FA mandatory for all users with the Administrator, Editor and Shop Manager roles. For Author and Contributor it is strongly recommended.

Strong, unique passwords are the foundation. WordPress 6.x generates strong passwords by default, but users often change them to ones that are easier to remember. Enforcing minimum complexity through a plugin (at least 12 characters, a mix of letters, numbers and special characters) is good practice. Passwords should not be reused on other sites.

Limiting login attempts blocks brute force attacks. By default, WordPress allows an unlimited number of login attempts, which is a gift to automated botnets. Limit Login Attempts Reloaded or Wordfence Login Security can block IP addresses after a set number of failed attempts (recommended: 3-5 attempts, blocked for 15-30 minutes).

Changing the login URL from the standard /wp-admin and /wp-login.php to something non-standard significantly reduces automated attacks. WPS Hide Login is a lightweight plugin that does exactly that.

Banning the username “admin” is a basic but still neglected measure. The default “admin” is the first thing botnets try. If you have it, create a new Administrator account with a unique name and delete the old one.

Automatic logout after inactivity protects against scenarios in which a user forgets an open session on a shared or public computer. The Inactive Logout plugin lets you configure a timeout per role, for example 15 minutes for Administrator and 60 minutes for Author.


Level 4 – Monitoring & Audit: monitoring activity

A man presents slides on “User roles in WordPress” to five colleagues seated around a modern conference table in the office.

You cannot protect what you do not monitor. Activity Log plugins record every action by every user: who logged in, when, from which IP address, what they changed and what they deleted.

WP Activity Log (formerly WP Security Audit Log) is the leading solution, with over 200,000 active installations. It records over 600 event types: content changes, user logins (successful and failed), settings changes, plugin installations, and changes to roles and capabilities. The free version is enough for most sites, and Pro adds email alerts, reports and integration with external SIEM systems.

Monitoring is especially important for online stores, where changes to the product catalogue, pricing and orders must be traceable. It is also a GDPR requirement: you must be able to prove who had access to personal data and what they did with it.

Our team configures Activity Log as a standard part of WordPress site maintenance, together with automated email alerts for suspicious activity, such as a login from a new IP address or multiple failed login attempts.

Privilege escalation: the real threat

Privilege escalation is an attack in which a user (or bot) with low privileges gains administrator rights by exploiting a vulnerability in a plugin, a theme or WordPress itself. It is one of the most dangerous types of vulnerability, because it gives the attacker full control without “breaking” anything visible.

In 2025 and early 2026, this type of attack became significantly more frequent. In January 2026, Wordfence reported a privilege escalation vulnerability in a custom fields plugin that affected 100,000 sites. In the same month, Patchstack identified a critical vulnerability in Frontend Admin by DynamiApps that allowed an unauthenticated user to become Administrator by manipulating a form. In November 2025, CVE-2025-12158 in the Simple User Capabilities plugin allowed privilege escalation in all versions.

Protection against privilege escalation involves several layers. Update all plugins and themes immediately when a new version is released: Patchstack data shows that attacks begin on average 5 hours after a vulnerability is published. Delete plugins and themes you do not use; they should not simply be deactivated but removed completely, because even a deactivated plugin can contain vulnerable code accessible via a URL. Use a Web Application Firewall (WAF): Wordfence and Patchstack offer virtual patches that block known exploits even before the developer has released an update. And last but not least, minimise the number of plugins that work with user roles and capabilities, because each such plugin is a potential point of vulnerability. We cover these protective measures in detail in our guide to security plugins.


User role audit checklist

We recommend auditing user accounts at least once a quarter. Here are the specific steps.

Review the list of all users (Users → All Users in the admin panel). For each account, ask: does this person still work on our site? If not, deactivate or delete the account. Inactive accounts with the Administrator role are especially dangerous.

Check the role of each active user and compare it with their actual tasks. If the copywriter has Administrator, downgrade them to Author. If a former freelancer still has Editor, remove them or downgrade them to Subscriber.

Check whether 2FA is enabled for all users with the Administrator, Editor and Shop Manager roles. If not, enable it and communicate the change clearly.

Review the Activity Log for unusual activity: logins from unknown IP addresses, mass content changes, installation of unknown plugins. If you use WP Activity Log, check the failed logins section.

Check whether there is a user named “admin”; if so, create a new Administrator account with a unique name and delete the old one. Finally, check whether there are custom roles that are no longer used. Redundant roles with unclear capabilities are a potential risk.

If you do not feel confident carrying out this audit yourself, you can use website analysis tools that include a review of the security configuration.


Roles when working with an agency or freelancers

A common scenario: you hire a web agency or freelancer for site development, design or maintenance. What access should you give them?

For a developer actively working on the site, the Administrator role is usually necessary, as they need to install plugins, edit code and configure settings. But several measures are critical here: create a separate account specifically for the developer (do not share your own), make 2FA mandatory, enable the Activity Log and, when the project ends, deactivate the account. Do not delete it straight away, as you may need to trace changes. Delete it after 30-60 days if no further work is needed.

For a copywriter or content manager, the Author or Editor role is enough. For an SEO specialist who works with meta tags and structure, Editor is suitable. For a designer who uploads visual assets but should not change code, Author with the additional upload_files capability (added through User Role Editor).

Professional agencies work with clear access protocols: separate accounts for each team member, 2FA, Activity Log and deactivation of accounts when the engagement ends. This is something you should discuss with every contractor before the project begins.


Roles on a multilingual WordPress site

On sites with several language versions (via WPML, Polylang or TranslatePress), role management takes on an extra dimension. WPML, for example, allows language access to be restricted: you can give an editor access only to the Bulgarian version, without them seeing or changing the English one.

This is particularly important for international teams, where different people manage different language versions. Without a language restriction, the Bulgarian editor could inadvertently change or delete content in the English version.

The configuration is done in WPML, Translation Management, and is available only to the Administrator. If you are planning a multilingual site, consider this setting from the very start, as correcting it after the fact is considerably more complicated.


Integrating Google tools with roles

Configuring Google tools (Analytics 4, Search Console, Tag Manager) also requires attention to roles. Google Analytics 4 has its own role system (Administrator, Editor, Analyst, Viewer), which should match the WordPress roles. A user who is an Author in WordPress should not be an Administrator in GA4.

When installing GA4 through Site Kit or manually through GTM, make sure the code can be edited only by a WordPress Administrator. A change to the tracking code by a user with a lower role can lead to data loss or, in the case of malicious action, to traffic data being redirected to someone else’s account.


The CreateWeb approach

On every website development project, we configure user roles as a standard part of the project, not as an extra service “if the client asks”. The process includes analysing the client’s team and workflows, creating custom roles where needed (via User Role Editor), configuring 2FA for all privileged accounts, installing and setting up Activity Log, documentation describing each role and its capabilities, and training the team to use them correctly.

With ongoing maintenance, a quarterly audit of user accounts is included in the plan: checking for inactive accounts, reviewing the Activity Log, updating security plugins and testing 2FA. The approach fits into our overall philosophy of security through quality hosting and regular backups.

Browse our portfolio for examples of completed projects or contact the team for a free consultation.


Frequently asked questions

What are the standard user roles in WordPress?

WordPress has six built-in roles. Super Admin exists only on Multisite and controls the whole network. Administrator has full control over a single site: plugins, themes, code, users, settings. Editor manages all content, their own and other people’s, but has no access to settings or plugins. Author writes, edits and publishes their own posts. Contributor writes drafts but cannot publish without approval. Subscriber can only read and edit their own profile. WooCommerce adds Shop Manager (day-to-day store management) and Customer (viewing their own orders).

Why is it dangerous to give all users the Administrator role?

Every Administrator account can install plugins, edit code and delete the entire site. If the password of such an account is compromised, through phishing, a reused password or brute force, the hacker gains full control. The principle of least privilege requires each user to receive only the permissions needed for their specific tasks. The copywriter gets Author, not Administrator.

What is the WordPress Access Control Pyramid and how is it applied?

It is a 4-level framework for access management: Level 1 Role Architecture (understanding the 6 roles and capabilities), Level 2 Role Assignment (PoLP, the right role for each task), Level 3 Account Protection (2FA, passwords, login limits) and Level 4 Monitoring & Audit (Activity Log, quarterly audit). The principle: you start from the base (understanding the roles) and build upwards. Perfect 2FA on an account with unnecessary Administrator rights still hands over full control if it is compromised.

How do I create a custom role in WordPress?

The easiest way is with the User Role Editor or PublishPress Capabilities plugin. Both offer a visual interface: you create a new role (or clone an existing one), then tick or untick specific capabilities such as edit_posts, upload_files, manage_categories and so on. Developers can also do it programmatically with the add_role() function in functions.php. Important: test changes in a staging environment before applying them to the live site.

What roles does WooCommerce add?

WooCommerce adds two roles: Shop Manager and Customer. Shop Manager has full access to products, orders, coupons and WooCommerce reports, but no access to plugins, themes, code or server settings. Customer can view and manage their own orders and profile. Shop Manager is the ideal role for someone running the store’s day-to-day operations, with no risk to its technical integrity.

What is privilege escalation and how do I protect myself?

Privilege escalation is an attack in which a user with low privileges gains administrator access through a vulnerability in a plugin or theme. Numerous such vulnerabilities were recorded in the WordPress ecosystem in 2025. Protection includes updating all plugins and themes immediately, deleting unused extensions, two-factor authentication, a Web Application Firewall (Wordfence or Patchstack), monitoring user activity and regularly auditing roles and accounts.

Does CreateWeb help with configuring user roles?

Yes. We configure user roles and capabilities as a standard part of building and maintaining WordPress sites. This includes analysing the team and workflows, creating custom roles, setting up 2FA for privileged accounts, installing Activity Log, documentation and training. With ongoing maintenance, a quarterly audit of user accounts is carried out.


Conclusion: access is security

The way you manage user roles directly determines how secure your WordPress site is. With 11,334 new vulnerabilities in 2025 (+42 %) and increasingly frequent privilege escalation attacks, correct access configuration is no longer optional but a necessity.

The WordPress Access Control Pyramid in this article provides a clear structure: Level 1 Role Architecture (understanding roles and capabilities), Level 2 Role Assignment (the principle of least privilege), Level 3 Account Protection (2FA, passwords, login limits) and Level 4 Monitoring & Audit (Activity Log, quarterly audit). The principle: you build from the bottom up, because skipping the base makes the upper levels pointless.

Grant the minimum necessary permissions, protect privileged accounts with 2FA, monitor activity with Activity Log and carry out a quarterly audit. These measures drastically reduce the attack surface without complicating the workflow.

If you want a WordPress site with properly configured roles and security from day 1, request a quote from CreateWeb for a free consultation. We will apply the WordPress Access Control Pyramid to your specific team and workflows.

Related specialist resources: WordPress security plugins, our central article on WordPress plugins, WooCommerce for a Bulgarian store, backup plugins, WordPress as a platform, quality web hosting, website analysis tools, Google Analytics 4, E-E-A-T for WordPress, our central SEO article, website development, website maintenance.

Read more: WordPress community.

/inspiration, expert advice and news

Последна актуализация: