Skip to content

Account and Security

John James Jacoby edited this page Sep 16, 2026 · 1 revision

Account and Security

The Account section groups credentials, language, and active authentication mechanisms.

Account section with email, password, language, sessions, and application passwords

Email

WordPress validates the email address and prevents reuse by another account. Changes can affect password recovery and administrative notifications.

Password

Use Set New Password to generate or enter a replacement. WordPress's password-strength and confirmation behavior remains in effect.

Language

Choose a personal administration language or inherit the site default. Only installed languages are accepted.

Sessions

The Sessions metabox can terminate other authenticated sessions while retaining the current one.

Application Passwords

When WordPress supports application passwords for the selected account, the Account section provides their standard creation and revocation interface.

Security guidance

  • Verify the selected user before changing credentials.
  • Use unique, lengthy passwords and multi-factor authentication where available.
  • Revoke sessions and application passwords that are no longer needed.
  • Do not paste passwords into issue reports, logs, or screenshots.

Clone this wiki locally