Product
Solutions
Compare
Resources
Get early access Talk to us
Users and access

WordPress user roles and permissions, explained

WordPress user roles decide what each person can do on a site, from reading posts to installing plugins. There are six: Super Admin, Administrator, Editor, Author, Contributor and Subscriber. Give everyone the lowest role that does the job, and if you run more than one site, use WordPress user management to keep roles in order everywhere.

Table of WordPress user roles and permissions: Administrators can do everything on a single site, Editors manage all posts and pages, Authors publish and upload their own posts, Contributors write drafts only, and Subscribers can only read and edit their profile
Default WordPress user roles and permissions on a single site, from the WordPress.org documentation.

The short answer

WordPress has six user roles: Super Admin (multisite only), Administrator, Editor, Author, Contributor and Subscriber. Each role is a bundle of permissions, called capabilities, that decides what a person can do on the site.

  • Administrator: everything on one site, including plugins, settings and users.
  • Editor: publishes and manages everyone's posts and pages.
  • Author: publishes their own posts and uploads media.
  • Contributor: writes drafts but cannot publish or upload.
  • Subscriber: reads and manages their own profile.

Give each person the lowest role that lets them do their job, and remove accounts as soon as people leave.

What are WordPress user roles and permissions?

A WordPress user role is a named set of permissions. WordPress calls each permission a capability: publish_posts lets someone publish, upload_files lets them add media, install_plugins lets them install plugins, and so on. When a person tries to do something, WordPress checks whether their role includes the matching capability.

That design keeps things simple. You do not set permissions person by person; you give each person a role, and the role carries the permissions. WordPress stores the roles and their capabilities in the database (in the options table, under wp_user_roles with the default table prefix), which is why plugins can add new roles or change existing ones.

Two things are worth knowing from the start. First, the person who installs WordPress automatically gets an Administrator account. Second, on a normal single site, the Administrator is effectively the top role. The Super Admin only appears when you turn a site into a multisite network.

The six default WordPress user roles explained

Super Admin

The Super Admin only exists on WordPress multisite. WordPress describes it as somebody with access to the network administration features and everything else. A Super Admin adds and removes sites, installs plugins and themes for the whole network and manages every user. On a multisite network, ordinary site Administrators lose several powers to the Super Admin, including installing plugins and themes, editing users and posting unfiltered HTML.

Administrator

An Administrator has access to all the administration features of a single site. They install, update and delete plugins and themes, change every setting under Settings, edit menus and widgets, and add, edit and remove users. They can also do everything an Editor can. Because this role can change anything, including who else has access, it should belong to as few people as possible.

Editor

An Editor can publish and manage posts, including the posts of other users. They also manage pages, moderate comments, manage categories and tags, and upload files. On a single site, Editors have the unfiltered_html capability, which lets them add raw HTML and JavaScript to content. What they cannot do is install plugins, change themes, edit menus and widgets, or change site settings. That makes Editor the natural role for content managers and for clients who look after their own pages.

Author

An Author can publish and manage their own posts. They upload images and files, publish, and edit or delete posts they have already published. They cannot touch pages, other people's posts or comments from other authors. It suits staff writers who you trust to publish without review.

Contributor

A Contributor can write and manage their own posts but cannot publish them. They also cannot upload files, which surprises many people: a Contributor writing a post cannot add their own images. Someone with the Editor or Administrator role reviews the draft, adds media and publishes. Contributor is the right role for guest writers and anyone whose work should be checked first.

Subscriber

A Subscriber can only manage their own profile and read content. Membership plugins, forums and online courses often use it, or a role based on it, for registered members. If your site does not need people to register, you should not have Subscribers at all.

WordPress user roles and capabilities compared

The table below sums up the default WordPress user roles and permissions, with the capabilities that separate each one from the role below it. The chart at the top of this page shows the same permissions as a grid.

WordPress user roles and capabilities compared
RoleIn one lineKey capabilitiesGive it to
Super AdminRuns a multisite networkEvery capability on every site in the networkThe network owner only
AdministratorFull control of one sitemanage_options, install_plugins, edit_users, edit_theme_optionsOne or two people who run the site
EditorManages everyone's contentedit_others_posts, publish_pages, moderate_comments, manage_categoriesContent managers, trusted clients
AuthorPublishes their own postspublish_posts, upload_files, edit_published_postsStaff writers
ContributorWrites drafts for reviewedit_posts, delete_posts (own drafts only)Guest and freelance writers
SubscriberReads and manages a profilereadMembers, readers, customers

Source: WordPress.org Roles and Capabilities documentation, checked 10 October 2026. Plugins can add capabilities to a role or create new roles.

One capability deserves a closer look: unfiltered_html. WordPress's own documentation warns that giving it to untrusted users can let them post malicious or badly formed code. On a single site, Editors and Administrators have it by default. If you do not need it, the DISALLOW_UNFILTERED_HTML constant in wp-config.php removes it from everyone, including Administrators.

Which role should you give each person?

The safe rule is the principle of least privilege, which NIST defines as restricting access to the minimum needed to do the assigned task. In WordPress terms: start from the lowest role that works and move up only when the job needs it.

Which WordPress role to give each person
PersonRecommended roleWhy
Site owner or lead developerAdministratorSomeone has to install plugins and change settings. Keep it to one or two people.
Marketing or content managerEditorPublishes and edits everyone's content without touching plugins or settings.
Client who edits their own pagesEditorFull control of content, no way to break the site by deactivating a plugin.
In-house writerAuthorPublishes their own posts and uploads images, cannot change anyone else's work.
Guest or freelance writerContributorSubmits drafts for review. An Editor checks and publishes them.
Store staff on WooCommerceShop ManagerRuns orders, products and coupons without full Administrator access.
Customers and membersSubscriber or CustomerCan log in and manage their own profile or orders, nothing more.
Agency or contractor for a projectThe lowest role that does the job, removed when the project endsLeftover accounts are a common way into a site.

Our recommendation, based on the default capabilities of each role.

How to change a user role in WordPress

You need an Administrator account (or another role with the promote_users capability) to change roles.

Change one person's role

  1. Open the user. In wp-admin, go to Users > All Users and click the name of the person.
  2. Pick the new role. Scroll to the Role dropdown and choose the role they need.
  3. Save. Click Update User at the bottom of the page. The change applies at their next page load.

Change the role of several users at once

  1. Go to Users > All Users.
  2. Tick the box next to each person you want to change.
  3. Choose a role from the Change role to dropdown above the list and click Change. WordPress confirms with the message "Changed roles."

Set the default role for new users

Under Settings > General, the New User Default Role decides which role new accounts get, both for people who register and for users you add by hand. If Anyone can register is ticked, keep the default role at Subscriber. Setting it higher lets strangers give themselves real permissions.

WordPress also stops you from changing your own role to one that can no longer manage users, so you cannot lock yourself out by accident.

WooCommerce and plugin user roles

Plugins often add their own roles. WooCommerce is the most common example. It adds two:

  • Customer: similar to a Subscriber. Customers can read content, edit their account and see their past and current orders.
  • Shop Manager: runs the store without full Administrator access. Shop Managers handle products, orders, refunds, coupons, customers and WooCommerce reports and settings, and they can create and edit posts and pages like an Editor. They cannot install plugins or change general site settings.

SEO, membership, learning and forum plugins add roles too. Before you give someone a plugin role, check what it actually includes on that site, because a plugin can add capabilities you did not expect. If you run several stores, see how to manage multiple WooCommerce stores safely.

How to edit WordPress user roles and permissions

There are two ways to edit roles or create a custom one.

With a plugin

Role editor plugins show each role's capabilities as checkboxes. User Role Editor (more than 700,000 active installs on WordPress.org) lets you change capabilities, add, copy and delete roles, assign capabilities to a single user and give one user several roles. Members (more than 300,000 active installs) does the same and adds content permissions, so you can hide pages from certain roles. Both are listed on the official Roles and Capabilities page.

With code

Developers use a few core functions:

  • add_role() adds a new role with a display name and a list of capabilities. It does nothing if the role already exists.
  • remove_role() deletes a role.
  • add_cap() and remove_cap() on a role, or on a single user, add or remove one capability.
  • current_user_can() checks whether the current user has a capability. WordPress's documentation discourages checking role names with it, because results can be unreliable. Check capabilities instead.
<?php
// Run once, for example on plugin activation.
add_role( 'seo_manager', 'SEO Manager', array(
    'read'              => true,
    'edit_posts'        => true,
    'edit_others_posts' => true,
    'edit_pages'        => true,
    'edit_others_pages' => true,
) );

Because roles live in the database, calling add_role() a second time with different capabilities changes nothing. Run role changes on plugin activation, and remove or update the role explicitly when you need to change it.

WordPress user role security best practices

  • Keep administrators to a minimum. Every Administrator account can install code and create other administrators.
  • One person, one account. Shared logins make the site's history meaningless and make removing access impossible without changing the password for everyone.
  • Remove people the day they leave. When you delete a user, WordPress asks who should own their content, so reassign it rather than deleting their posts.
  • Review roles every month. Look for administrators you do not recognize and accounts nobody has used in months. Make it part of your WordPress site monitoring routine.
  • Turn off the file editor. DISALLOW_FILE_EDIT in wp-config.php removes the ability to edit plugin and theme code from wp-admin for every user.
  • Watch application passwords. Since WordPress 5.6, users can create application passwords for the REST API. Each one is tied to a user account, so remove them when the account no longer needs them.
  • Use two-step login and avoid the username "admin". Both come straight from WordPress's hardening guide.

An audit log of user activity is the other half of this. Roles decide what people can do; the log shows what they actually did.

Managing WordPress user roles across multiple sites

Everything above happens inside one site. If you look after ten, thirty or a hundred WordPress sites, the same jobs repeat on every one: a new developer needs an account everywhere, a contractor leaves and their Administrator account stays behind on eleven sites, a client asks you to downgrade an ex-employee. Nothing about it is hard. It is just easy to miss one site, and the missed account is the one that matters.

This is the problem WPCentrify was built for. (Disclosure: WPCentrify is our product.) Its WordPress user management works on every connected site from one screen, and it is part of the wider WordPress website management platform that also handles updates, backups, uptime and security.

  • Every user and role on every site, live. List, search and filter users by role on any connected site. Results come from the site itself, not a cached copy.
  • Add one person to many sites in one action, with the role you choose, and see the result for each site.
  • Remove someone everywhere at once when they leave, instead of working down a list and hoping you got them all.
  • Custom roles included. Roles are read from each site, so WooCommerce, membership and custom roles appear and can be assigned.
  • Find who is where. See which sites a person has an account on without opening each one.
  • Deletion asks the right question. You pick who inherits a removed user's content before anything is deleted.
  • Every change recorded in the activity log, with who made it, on which site and what WordPress returned.
  • No shared passwords for your team. One-click login signs each person in as themselves, with a role cap you set per person and per site.

Two more details matter for security. WPCentrify does not keep a standing administrator account on your sites: the connector authenticates with a scoped key unique to each site and signs every instruction. And access to WPCentrify itself is a separate set of team and client permissions, so someone can be allowed to manage users on a client site without being allowed to disconnect it. Team members are never charged as seats. And Sentinel security monitoring emails you the moment a new administrator account appears on any site.

Sources

All sources checked on 10 October 2026.

Answers

Questions about WordPress user roles

A single WordPress site has five default roles: Administrator, Editor, Author, Contributor and Subscriber. A multisite network adds a sixth, the Super Admin, who controls every site in the network.

An Editor manages content: they can publish, edit and delete anyone's posts and pages, moderate comments and manage categories. An Administrator can do all of that and also install plugins and themes, change settings, edit menus and widgets, and add or remove users.

No. A Contributor can write and edit their own drafts but cannot upload files or publish. An Editor or Author has to add the images and publish the post, or you give the person the Author role.

Go to Users, click the person, choose a new role from the Role dropdown and click Update User. To change several people at once, tick them on the Users screen, pick a role from Change role to and click Change. You need an Administrator account to do this.

As few as possible, usually one or two people who actually manage the site. Everyone else should get the lowest role that lets them do their job, because every administrator account is a full set of keys to the site.

If the client only edits pages and posts, Editor is usually enough and protects them from breaking plugins or settings by accident. If they own the site and want full control, give them an Administrator account of their own rather than sharing yours.

Use a role editor plugin such as User Role Editor or Members, or call add_role() in a small plugin that runs on activation. Roles are saved in the database, so changing the code later does not change a role that already exists.

WordPress can store more than one role per user, but the standard Users screen only shows and edits one. Plugins such as Members and User Role Editor let you assign several roles to the same person.

The Super Admin exists only on WordPress multisite. They manage the whole network: they add and remove sites, install plugins and themes for every site, and manage users across the network. On a multisite network, site Administrators cannot install plugins.

Use a management platform instead of logging in to each site. WPCentrify lists the users and roles on every connected site, adds or removes one person across many sites in one action, reads custom roles from each site and records every change in an activity log.

Early access

Manage users and roles on every site from one place

List, add, re-role and remove WordPress users across every site you manage, with every change recorded.

Free during early access. No credit card required.