How to Create a New User on WordPress
There are plenty of reasons you might want to add a new user to your WordPress website — maybe a staff member needs editing access, your nonprofit is bringing on a volunteer blogger, or your agency partner needs temporary developer permissions.
WordPress makes this simple by offering several predefined user roles, each with its own permissions. Knowing which role to assign is important for keeping your site organized, secure, and functioning smoothly.
Here’s a breakdown of how WordPress user roles work, when to use each one, and how to safely add new users to your website.
Understanding WordPress User Roles
WordPress comes with five default user roles (and some hosts add more). Each role determines what actions a person can take on your site. Giving someone too much access can put your content — or your entire site — at risk, so choosing wisely is a key part of website security.
Let’s walk through what each role can do.
Administrator (Full Access)
This is the highest level of access in WordPress. Administrators can do anything, including:
- Adding, editing, or deleting content
- Installing and deleting plugins and themes
- Creating and removing users
- Changing security settings
- Modifying core settings
Only trusted, tech-comfortable people should have admin access.
Administrators have full control of your site — and full responsibility for it.
Editor (Content Manager)
Editors manage all content across the site, including:
- Editing, publishing, and deleting any page or post
- Moderating comments
- Organizing categories and tags
- Uploading media
Editors cannot:
- Install plugins
- Change settings
- Add or edit users
This role is ideal for communications staff, content writers, and team members responsible for keeping your website updated.
Author (Publishes Their Own Content)
Authors can:
- Write, edit, publish, and delete their own posts
- Upload their own images
Authors cannot:
- Create categories (but can choose from existing ones)
- Edit or delete others’ posts
- Access sitewide settings
This role works well for recurring blog contributors or program leaders who only need to publish their own content.
Contributor (Writes but Cannot Publish)
Contributors can:
- Write and edit their own posts
- Submit posts for review
But they cannot:
- Publish posts
- Upload images or files
- Edit content after it’s approved
This role is a great fit for guest writers, interns, or volunteers who contribute content occasionally.
Subscriber (Minimal Access)
Subscribers only have access to:
- Logging in
- Updating their profile
- Reading posts (if your content is restricted)
They cannot create or edit content.
This is commonly used for membership sites, private content areas, or communities needing login-only access.
How to Create a New WordPress User (Step-by-Step)
You must be an Administrator to add new users.
Step 1 — Log In to Your WordPress Dashboard
Navigate to:
yourwebsite.com/wp-admin
Enter your username and password.
Step 2 — Go to Users → Add New
On the left sidebar, click:
Users → Add New
This will open a form where you’ll enter the new user’s information.
Step 3 — Fill Out the User Details
You’ll see several fields to complete:
Username
This is permanent once created. Good formats include:
- First initial + last name (sgraybill)
- First name + last initial (sarag)
- Full name if needed
Avoid using email addresses as usernames — it’s more secure to keep these separate.
Email Address
This is where the login instructions will be sent.
It must be a real, accessible email.
First & Last Name (Optional but Helpful)
Populating these fields makes your site more organized and personal.
Website (Optional)
Not required unless the user has a public author profile.
Step 4 — Assign a User Role
Scroll down to Role and select the level of access they need.
If you’re unsure:
- Give the lowest role necessary
- You can always raise permissions later
This protects your site — and your team.
Step 5 — Notify the User
Make sure “Send User Notification” is checked so WordPress will email login instructions.
Once you click Add New User, WordPress generates a password and sends the new user an email with everything they need to sign in.
Additional Security Tips
As WordPress evolves, security best practices evolve too. Before adding new users, keep these tips in mind:
1. Use strong passwords or password managers
Weak passwords are one of the most common causes of hacked websites.
2. Enable two-factor authentication (2FA)
Many security plugins — like Wordfence or iThemes Security — now offer easy 2FA setup for all users.
3. Remove old users regularly
Former employees, volunteers, or contractors shouldn’t keep access.
4. Avoid multiple administrators
In most cases, two administrators are plenty.
5. Use role-specific tools
Plugins like Members or User Role Editor allow you to customize permissions if the built-in roles don’t meet your needs.
When to Give a Developer Temporary Access
If you’re working with a contracted WordPress developer, it’s common to create an account for them — but only when needed.
Best practices:
- Give Administrator access only when absolutely necessary
- Downgrade or delete their account when the work is complete
- Use a unique developer login rather than sharing your own credentials
This protects you, your data, and your team.
Need Help Managing User Permissions Safely?
If you’re unsure which roles your team needs — or if you want help auditing who currently has access — we’re here to help.
Schedule a WordPress support consultation and we’ll walk through it together.
