
How to Enable Two-Factor Authentication on WordPress?
Most WordPress compromises do not start with a clever exploit. They start with a password: reused from a breached site, guessed by a bot that has been hammering wp-login.php for weeks, or typed into a convincing phishing page. Once an attacker logs in as an administrator, they can install a plugin, add a user, or inject code, and no firewall rule will notice because the login was "valid." Two-factor authentication (2FA) breaks that chain. Even with the correct password, an attacker cannot log in without the second factor, usually a six-digit code from an app on the user's phone.
This article covers how to enable two-factor authentication on WordPress from start to finish: what WordPress core does and does not include, setting up the official Two Factor plugin, configuring an authenticator app and backup codes, controlling which methods are allowed, enforcing 2FA for administrators with a small snippet, how 2FA interacts with the REST API and application passwords, alternative plugins, and how to recover when someone loses their phone.
Does WordPress Have Built-In Two-Factor Authentication?
No. As of WordPress 7.1, core still authenticates users with a username or email and a password only. Two-factor authentication comes from plugins. The most direct option is Two Factor, a plugin maintained by WordPress contributors and published on WordPress.org. It follows core coding standards, uses core APIs, and has no premium upsells.
| Login factor | Example | What it protects against |
|---|---|---|
| Something you know | Password | Casual access |
| Something you have | Authenticator app, security key | Stolen, reused, or guessed passwords |
| Something you can recover with | Backup codes | Losing the device with the authenticator app |
2FA is one layer of a broader security setup. Strong passwords, updates, limited admin accounts, and a firewall still matter. For the bigger picture, see how to improve the security of the WordPress website.
Two-Factor Methods Compared
The Two Factor plugin supports these methods, which it calls providers:
| Provider | How it works | Security | Notes |
|---|---|---|---|
| Authenticator App (TOTP) | Six-digit code from an app, changes every 30 seconds | High | Works offline; recommended primary method |
| Backup Codes | Ten single-use codes generated in advance | Medium | Recovery method; store them safely |
| Email Codes | One-time code sent to the account's email address | Medium | Only as strong as the email account |
Hardware security keys and passkeys are available through the separate Two-Factor Provider: WebAuthn add-on plugin. The older FIDO U2F method was removed from Two Factor because browsers dropped support for it.
For most sites, require an authenticator app plus backup codes for administrators and editors. Email codes are better than nothing, but anyone who controls the user's inbox controls their second factor too.
Installing the Two Factor Plugin
- Log in as an administrator and go to Plugins → Add New Plugin.
- Search for Two Factor. Choose the plugin published by WordPress.org Contributors.
- Click Install Now, then Activate.
Or with WP-CLI:
# Terminal
wp plugin install two-factor --activate
Activating the plugin does not force anyone to use 2FA. Each user turns it on in their own profile. Users without 2FA configured keep logging in with just a password until you enforce it, which is covered later in this article.
Setting Up an Authenticator App
Do this for your own administrator account first.
- Install an authenticator app on your phone. Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden, and most other password managers support standard TOTP codes.
- In WordPress, go to Users → Profile.
- Scroll to the Two-Factor Options section.
- Under Authenticator App, a QR code and a text key are shown. Scan the QR code with the app, or type the key manually.
- Enter the six-digit code the app shows to confirm, then submit.
- Tick Authenticator App as enabled and select it as your primary method.
- Click Update Profile.
From now on, the login screen asks for your password and then for the current six-digit code.
If codes are rejected, check the clock first. TOTP codes depend on time, so the server and phone must agree within about 30 seconds. Phones sync time automatically. Servers should run NTP, for example chrony or systemd-timesyncd.
Generating Backup Codes
Backup codes are what you use when your phone is lost, broken, or reset. Set them up immediately after the authenticator app:
- In Users → Profile → Two-Factor Options, find Backup Codes.
- Click Generate new backup codes.
- Download or copy the ten codes and store them somewhere you can reach without your phone, such as a password manager on another device or a printed copy in a safe place.
- Enable Backup Codes as a method and click Update Profile.
Each code works once. Generating a new set invalidates the old ones. When you get low, generate a fresh set.
Controlling Which Methods Are Available
Administrators can disable methods site-wide without code. The plugin adds a settings screen under Settings → Two-Factor where you can turn individual providers off. For example, disabling Email Codes forces users to choose an authenticator app.
Developers can do the same in code with the two_factor_providers filter. Array keys are provider class names:
// wp-content/mu-plugins/wsm-two-factor.php
<?php
/**
* Plugin Name: WSM Two-Factor Policy
* Description: Site-specific two-factor rules.
*/
add_filter( 'two_factor_providers', function ( array $providers ): array {
// Remove email codes so users must use an authenticator app or backup codes.
unset( $providers['Two_Factor_Email'] );
return $providers;
} );
A must-use plugin in wp-content/mu-plugins/ is a good home for security policy, because it loads automatically and cannot be deactivated from the Plugins screen.
Be careful when removing the email provider on an existing site. If a user's only enabled method disappears, the plugin falls back to a provider it can use for them, Email by default, controlled by the two_factor_fallback_provider_for_user filter. Have users switch to an authenticator app before you disable email codes.
Enforcing Two-Factor Authentication for Administrators
The Two Factor plugin lets every user opt in, but it does not force anyone to enroll. On most sites, you want 2FA to be mandatory for anyone who can change the site: administrators, editors, and shop managers.
The following must-use plugin sends privileged users to their profile until they have set up two-factor authentication. They can still log in with their password, but they cannot use any other admin screen until 2FA is active.
// wp-content/mu-plugins/wsm-require-two-factor.php
<?php
/**
* Plugin Name: WSM Require Two-Factor
* Description: Requires two-factor authentication for privileged roles.
*/
const WSM_2FA_REQUIRED_ROLES = array( 'administrator', 'editor', 'shop_manager' );
function wsm_user_requires_two_factor( WP_User $user ): bool {
return (bool) array_intersect( WSM_2FA_REQUIRED_ROLES, (array) $user->roles );
}
add_action( 'admin_init', function (): void {
if ( ! class_exists( 'Two_Factor_Core' ) || wp_doing_ajax() ) {
return;
}
$user = wp_get_current_user();
if ( ! $user->exists() || ! wsm_user_requires_two_factor( $user ) ) {
return;
}
if ( Two_Factor_Core::is_user_using_two_factor( $user->ID ) ) {
return;
}
global $pagenow;
if ( 'profile.php' === $pagenow ) {
return; // Let them reach the screen where 2FA is set up.
}
wp_safe_redirect( admin_url( 'profile.php' ) );
exit;
} );
add_action( 'admin_notices', function (): void {
if ( ! class_exists( 'Two_Factor_Core' ) ) {
return;
}
$user = wp_get_current_user();
if ( wsm_user_requires_two_factor( $user ) && ! Two_Factor_Core::is_user_using_two_factor( $user->ID ) ) {
echo '<div class="notice notice-error"><p>';
echo esc_html__( 'Your role requires two-factor authentication. Set up an authenticator app and backup codes in Two-Factor Options below to continue.', 'wsm' );
echo '</p></div>';
}
} );
How it works:
Two_Factor_Core::is_user_using_two_factor()returns true once the user has a primary two-factor method configured.- The
class_exists()check means that if the Two Factor plugin is deactivated, the snippet does nothing instead of locking everyone out of the admin. - AJAX requests are skipped so the profile screen can still save settings.
- The notice explains why the user keeps landing on their profile.
Test this on a staging site first, with a second administrator account that does not have 2FA yet. Make sure your own account is fully set up before you deploy it to production.
If you prefer a settings screen with grace periods, enforcement policies per role, and reminder emails, the alternative plugins below offer that out of the box.
Two-Factor Authentication and the REST API
Two-factor authentication protects the browser login form. Other ways of authenticating need their own rules:
- REST API and XML-RPC with a username and password. Once a user has 2FA enabled, the Two Factor plugin blocks plain password authentication for API requests by that user. Otherwise, an attacker with the password could skip 2FA entirely by calling the API.
- Application passwords. These are separate, revocable credentials for scripts and apps, and they keep working for users with 2FA. This is the intended way to connect a mobile app, an automation tool, or a headless frontend. See how to use application passwords in WordPress for setup and security advice.
- XML-RPC. If nothing on your site uses it, disable it entirely, which removes an old and frequently attacked endpoint.
Managing 2FA with WP-CLI
The Two Factor plugin adds a wp two-factor command namespace, which is the fastest way to audit and support users:
# Terminal
# Show a user's 2FA status
wp two-factor status editor@example.com
# List registered providers
wp two-factor list-providers
# Generate a fresh set of backup codes for a user
wp two-factor backup-codes generate jane --count=10
# Clear login rate limiting after too many failed attempts
wp two-factor unlock jane
# Reset all two-factor settings for a user who lost their device
wp two-factor disable jane --yes
Commands accept a user ID, login, or email address. Authenticator app setup still has to happen in the browser, because the user must scan a QR code that only they should see.
To audit every administrator at once:
# Terminal
for user in $(wp user list --role=administrator --field=user_login); do
echo "== $user"
wp two-factor status "$user"
done
Recovering from a Lockout
People lose phones. Plan the recovery process before you need it:
- Use a backup code. On the two-factor login screen, choose the option to use a different method and enter one of the saved backup codes.
- Ask another administrator. An administrator can open Users → All Users, edit the locked-out user, and reset or change their two-factor options.
- Use WP-CLI.
wp two-factor disable <user> --yesresets the user's two-factor settings. They log in with their password and set up 2FA again. - Last resort without WP-CLI. Connect with SFTP or your host's file manager and rename
wp-content/plugins/two-factortotwo-factor-disabled. This deactivates the plugin for everyone, so log in, fix the account, rename the folder back, and reactivate the plugin immediately. Keep a recent backup before making changes like this, as covered in how to create a backup for a WordPress website.
On sites with a single administrator, backup codes are not optional. They are the difference between a five-second recovery and editing files on the server.
Alternative Two-Factor Plugins
The Two Factor plugin is lean and dependable. Other plugins add management features at the cost of more code:
| Plugin | Strengths |
|---|---|
| Two Factor | Maintained by WordPress contributors, minimal, WP-CLI commands |
| Wordfence Login Security | TOTP and recovery codes, can require 2FA by role, login CAPTCHA |
| WP 2FA | Setup wizard, enforcement policies, grace periods for users |
| Solid Security | 2FA as part of a broader security suite |
Whichever you choose, use only one two-factor plugin at a time. Two plugins hooking the same login flow lead to confusing prompts and lockouts.
Common Problems and Fixes
- Codes from the authenticator app are always rejected. The server clock is wrong. Check it with
date -uon the server and enable NTP time sync. - Users are not prompted for a code at all. Activating the plugin does not enable 2FA for users. Each user must configure a method in their profile, or you must enforce it as shown above.
- A mobile app or integration stopped working after enabling 2FA. It was logging in with the user's main password. Create an application password for it instead.
- The two-factor screen loops back to the login form. A caching plugin or CDN is caching
wp-login.php. Exclude the login page and admin from page caching. - Email codes never arrive. WordPress mail is unreliable on many hosts. Configure SMTP, or switch the user to an authenticator app, which does not depend on email.
- Locked out after too many attempts. The plugin rate-limits failed codes. Wait, or run
wp two-factor unlock <user>. - Everyone lost 2FA after a migration. Two-factor settings are stored in user meta, so a database migration keeps them. If only files were moved, re-import the database.
Two-Factor Authentication FAQ
No. WordPress core authenticates users with a password only. Two-factor authentication is added with a plugin such as Two Factor, which is maintained by WordPress contributors and published on WordPress.org.
Use an authenticator app as the primary method and keep backup codes as the recovery method. Email codes are convenient but only as secure as the user's email account, so avoid them for administrators.
Yes. The Two Factor plugin lets users opt in, so enforcement needs a small must-use plugin that redirects privileged users to their profile until they set up 2FA, or a plugin such as Wordfence Login Security or WP 2FA that offers role-based enforcement in its settings.
Log in with one of your backup codes, then set up the authenticator app again on your new phone and generate fresh backup codes. Without backup codes, another administrator or someone with WP-CLI access can reset your two-factor settings.
Integrations that log in with a user's main password stop working once that user enables two-factor authentication, which is intentional. Create an application password for each app or integration instead, since application passwords continue to work.
Require it for anyone who can change content or settings, such as administrators, editors, and shop managers. For customers and subscribers, offering it as an option is usually enough, because forcing it adds support load without protecting much.
Conclusion
Passwords alone are not enough to protect a WordPress administrator account, and WordPress core does not offer anything more out of the box. The official Two Factor plugin closes that gap with a few minutes of setup: install it, configure an authenticator app and backup codes on your own account, disable email codes if you can, and enforce 2FA for every privileged role with a small must-use plugin or a plugin that has enforcement built in.
Then plan for the failure cases. Make sure every administrator has saved backup codes, know the wp two-factor commands for resetting a user, and move integrations to application passwords. With that in place, a leaked or guessed password is no longer enough to take over your site.
Here are some useful references for going deeper on WordPress two-factor authentication:
- WordPress.org Plugins: Two Factor — the plugin page with setup instructions, providers, filters, and WP-CLI commands.
- GitHub: WordPress/two-factor — source code, issues, and development discussion.
- WordPress Developer Resources: Two-Step Authentication — background on multi-factor authentication for WordPress sites.
- WordPress Developer Resources: Hardening WordPress — the official security hardening guide.
- WordPress Developer Resources: Must Use Plugins — how mu-plugins load and why they suit site-wide policies.


