Get a free website with any plan

See how
WORDPRESS

Users and roles: what each role can do

Last updated

IN SHORT

WordPress provides five built-in roles to control user access in wp-admin: Administrator, Editor, Author, Contributor, and Subscriber. On your Flashcloud site, assign each user the lowest role needed for their specific work. This protects site settings by keeping full management restricted to the site owner.

WordPress ships with five built-in roles: Administrator, Editor, Author, Contributor, and Subscriber. Each one controls what a user can see and touch in wp-admin. If you're adding a client, a writer, or a freelancer to your site, give them the lowest role that lets them do their job. You almost never need to hand out Administrator.

The built-in roles cover most sites without any extra plugin. Reach for a role-management plugin only when you need something more specific, like limiting an Editor to one category or letting an Author moderate comments.

What each role can do

Administrator has full control: themes, plugins, users, settings, and every post on the site. Reserve this for the site owner and whoever manages the technical side. Every extra admin account is another password that can be phished or reused elsewhere, so keep the list short.

Editor can write, edit, publish, and delete any post or page, including ones written by other users. Editors can also manage categories, tags, and comments, but they can't install plugins, switch themes, or add new users. This is the right role for a content manager or lead writer who needs to oversee everyone else's work.

Author can write, edit, publish, and delete their own posts, and upload media. They cannot touch anyone else's content and cannot see site settings. Good for a regular contributor you trust to publish without review.

Contributor can write and edit their own posts but cannot publish them. Their work sits as a draft until an Editor or Administrator reviews and publishes it. Use this for guest writers or new team members until you're confident in their judgment. Contributors also can't upload media directly, which trips people up: if a Contributor needs to submit an image with a draft, an Editor will need to add it during review.

Subscriber can log in and manage their own profile, nothing else. This role exists mainly for membership sites or sites where commenting requires an account.

Assigning and changing roles

Go to wp-admin → Users → All Users. Click a user to edit their profile, or use Add New to invite someone fresh. The Role dropdown near the bottom of the profile sets their permissions. Changes take effect immediately on save; the user doesn't need to log out and back in.

On most hosting accounts, the account you create when you first install WordPress is an Administrator by default. Add everyone else below that.

The block editor covers most day-to-day work

For writing and publishing, the block editor is all any of these roles need. Editors and Authors compose posts directly in blocks, no plugin required. Contributors do the same, they just can't hit publish themselves.

Where a plugin earns its place is more granular control: restricting an Editor to specific categories, giving a Shop Manager role for WooCommerce, or creating a custom role that mixes permissions from different built-in roles. Popular options like "User Role Editor" or "Members" let you check and uncheck individual capabilities instead of accepting the default bundle. Install one only when the built-in five don't fit, since every active plugin is one more thing to keep updated and one more potential conflict if your site is already running plugin-heavy (see My WordPress site is slow for why that matters).

Safe practices for multi-user sites

A few habits keep a multi-author site from turning into a mess:

  • Give each person their own login. Shared accounts make it impossible to tell who changed what, and if one password leaks, every contributor is exposed.
  • Match the role to the job, not the person's seniority. A trusted freelancer writing one post a month is still an Author, not an Editor.
  • Before a big theme switch, plugin update, or structural change, test it on a staging copy of your site first rather than editing live.
  • Take a backup before changing anyone's role in bulk, especially if you're using a role-editing plugin that can accidentally strip capabilities from an entire role at once. Your account has nightly backups by default, but see backing up your WordPress site for more on how backups work if you want a fresh one first.
  • Remove accounts for people who've left. An old Contributor account is low risk; an old Administrator account is not.

When to contact support

If a user's role looks right but they still can't access something they should, or you're locked out of the only Administrator account, open a ticket from Support in the portal. It's real people, not a bot, and they can help sort out account access issues that aren't obvious from the Users screen.

Common questions

Why can't my contributor upload images?

Contributors cannot upload media directly under default WordPress permissions. An editor or administrator must add the image to the post during draft review.

Do users need to log out when their role changes?

No, role changes take effect immediately on save. The user does not need to log out and log back in.

What is the difference between an editor and an author?

Editors can publish, edit, and delete any post on the site, while authors can only manage their own posts. Editors can also manage tags, categories, and comments.

What do I do if I get locked out of my admin account?

Open a ticket through Support in the portal. The Flashcloud support team can assist with access issues when you cannot reach the WordPress admin screen.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.