Two-Factor Authentication for WordPress, Done Properly
Which 2FA method to enforce for which role, how to avoid locking yourself out, and why app-based codes beat SMS for a WordPress admin.

In this article
Most WordPress compromises I clean up do not start with a clever exploit. They start with a password: reused from a breached site, guessed by a bot that tried a few thousand combinations, or typed into a convincing fake login page. Two-factor authentication shuts most of those doors, because a stolen password alone is no longer enough.
The reason many sites still do not use it is fear of the lockout: the admin who changes phones and cannot get back in. So this guide deals with recovery first, then the methods, then the rollout. Get those three right and 2FA is close to invisible in daily use.
Why a strong password stopped being enough
A strong, unique password still matters, but it only protects against guessing. It does nothing when the password itself leaks — through a data breach elsewhere, malware on a team member's laptop or a phishing email. Credential lists from old breaches are tried against WordPress logins constantly, and any account that reused a password is exposed.
A second factor means the attacker also needs something only the user has: a code from their phone, a hardware key or a passkey stored on their device. That turns a leaked password from a breach into a non-event.
TOTP, passkeys, email codes and SMS, ranked
- Passkeys and hardware security keys (WebAuthn) are the strongest option. They are bound to the real domain, so they cannot be phished by a lookalike login page, and there is no code to intercept.
- Authenticator app codes (TOTP) from apps such as Google Authenticator, Microsoft Authenticator, 1Password or Bitwarden are the practical default. They work offline and are not tied to a phone number.
- Email codes are better than nothing but weak, because anyone who controls the inbox controls the login, and email is often the account that was compromised in the first place.
- SMS codes are the weakest. SIM-swap attacks, number porting and message interception are real, and the phone number is often public. Use SMS only when nothing else is possible.
Choosing a plugin
WordPress core does not include two-factor login, so you need a plugin. The community-maintained Two Factor plugin is lightweight and supports TOTP, email codes, backup codes and security keys. Wordfence Login Security, available on its own without the full firewall, adds TOTP with role-based enforcement and recovery codes. WP 2FA focuses on enforcement policies and a guided setup for users.
Whichever you choose, check three things before installing: that it can enforce 2FA by role rather than leaving it optional, that it issues backup codes, and that it has been updated recently. A login plugin that stops being maintained is a security liability rather than a protection.
Enforcing by role, so editors are not the weak link
Turning 2FA on only for administrators is the most common half-measure. An editor account can publish content to the whole site, which is all an attacker needs to inject a spam link or a malicious script. Shop managers in WooCommerce can see customer data and change orders. Any role that can publish, upload, install or manage users should be required to use a second factor.
Subscribers and customers are a different question. Forcing 2FA on every WooCommerce customer adds friction at checkout for little gain; make it available, not mandatory. Most enforcement settings let you apply the rule to selected roles and give users a grace period of a few days to set it up.
Recovery: codes, a second admin and the WP-CLI escape hatch
Every lockout I have dealt with had the same story: one admin account, 2FA on a phone, and the phone lost, reset or replaced. Plan for it before it happens.
- Make every user generate backup codes when they enrol, and store the administrator's codes in a password manager, not in a file on the desktop.
- Keep at least two administrator accounts belonging to different people, each with their own second factor, so one can reset the other.
- Know your escape hatch. With SSH access, wp plugin deactivate followed by the plugin's folder name turns 2FA off in seconds. With only SFTP, renaming the plugin's folder does the same thing.
- For the Two Factor plugin specifically, a user's enrolled methods live in user meta keys beginning with _two_factor, so removing that meta with WP-CLI resets one person without disabling 2FA for everyone.
- Write the recovery steps down where the next developer will find them. A recovery plan that lives only in your head does not survive staff changes.
Rolling it out to a client team without a support queue
Announce it before enforcing it. A short message explaining what will change, which app to install and when enforcement starts prevents most of the support requests. Enable enforcement with a grace period so people set it up at a convenient time rather than at the moment they need to publish something urgent.
Sit with the least technical person on the team for their setup. If they can do it, everyone can, and you will find any confusing step in the plugin's flow before the rest of the team hits it.
What 2FA does not protect, and what to pair it with
Two-factor authentication protects the login form. It does nothing about a vulnerable plugin that lets an attacker in without logging in at all, a stolen session cookie on an infected computer, or an application password created for an integration and left forgotten. Keep plugins updated, remove the ones you do not use, and review application passwords under each user's profile.
Pair it with rate limiting on the login page, unique passwords from a password manager, the least privileged role each person actually needs, and regular, tested backups. 2FA is one of the highest-value security steps you can take on a WordPress site, but it is still one layer of several.
Frequently asked questions
What is the best two-factor authentication plugin for WordPress?
The community Two Factor plugin, Wordfence Login Security and WP 2FA are all solid choices. Pick one that can enforce 2FA by user role, issues backup codes and is actively maintained. For most sites, authenticator app codes with backup codes are the right default.
How do I get back into WordPress if I lose my 2FA device?
Use one of your backup codes, or ask another administrator to reset your 2FA. If neither is possible, deactivate the 2FA plugin with WP-CLI using wp plugin deactivate, or rename its folder in wp-content/plugins over SFTP, then log in and set 2FA up again.
Should I use SMS or an authenticator app for WordPress?
Use an authenticator app, or better still a passkey or hardware key. SMS codes can be intercepted through SIM-swap and number-porting attacks. Authenticator apps work offline and are not tied to a phone number, which makes them both safer and more reliable.
Can I require 2FA only for administrators?
Yes, most 2FA plugins can enforce it by role, but administrators alone is not enough. Require it for every role that can publish content, upload files, manage users or handle orders, such as editors and WooCommerce shop managers. Leave it optional for customers and subscribers.
Does two-factor authentication slow down the WordPress login?
Only by the few seconds it takes to enter a code, and most plugins let users mark a trusted device so they are not asked on every login. It has no effect on front-end page speed, because it only runs on the login screen.