How to Change Two Factor Authentication Phone Number on WordPress

Written by: Abigail Ivy
Published on:

How to Change Two Factor Authentication Phone Number on WordPress

If you need to update the phone number tied to WordPress two-factor authentication, the exact steps depend on the plugin or login method you use.

This guide explains the most common ways to change it, plus what to do if you are locked out.

Two-factor authentication adds a second verification layer through SMS, an authenticator app, or a security plugin.

Changing that phone number is usually simple once you know where the setting lives, but the process can be confusing when the account owner, admin role, or recovery options are limited.

What two-factor authentication phone numbers are used for

A two-factor authentication phone number is typically linked to one of three login security methods: SMS verification, voice call verification, or account recovery.

In WordPress, this is often managed through a security plugin such as Wordfence, miniOrange, Duo Security, or a hosting provider’s login protection layer.

In some setups, the phone number is not stored in WordPress core at all.

Instead, it is saved inside a plugin dashboard, a connected identity provider, or the hosting account that controls website access.

That distinction matters because you may need to update the number in a separate system before WordPress recognizes the change.

Before you change the phone number

Before updating the number, confirm which login protection system is active on the site.

This prevents you from changing the wrong account or missing a secondary security setting.

  • Identify the plugin or service handling two-factor authentication.
  • Check whether the number is used for login codes, recovery codes, or admin alerts.
  • Make sure you still have access to the current account email.
  • Keep backup codes or an alternative authentication method available.

If your site uses an authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy, the phone number may only be relevant for recovery or SMS fallback.

If the site uses SMS codes directly, the number is part of the main login process and must be updated carefully.

How to change two factor authentication phone number on WordPress in a plugin

Most WordPress sites rely on a plugin for two-factor authentication, and the update usually happens in the plugin’s account settings.

The steps vary, but the process is often similar across major security tools.

Update the number in your profile or security settings

Log in to WordPress with your current authentication method, then open your user profile or the plugin’s security settings.

Look for a section labeled phone number, recovery phone, SMS authentication, or trusted device settings.

  1. Go to your WordPress dashboard.
  2. Open Users, Profile, or the security plugin menu.
  3. Find the current phone number field.
  4. Replace it with the new number.
  5. Save changes and confirm the new number if prompted.

Some plugins require you to verify the new number by entering a code sent by text message.

Others may require you to disable SMS 2FA, re-enable it, and then register the new number from scratch.

Re-enroll the number if the plugin stores it separately

In certain security setups, the phone number is tied to a device enrollment record rather than a simple profile field.

In that case, you may need to remove the old number or device and add the new one as a fresh verification target.

For example, a security plugin may ask you to:

  • Deactivate the current phone-based verification method.
  • Remove the old phone number from the user record.
  • Restart setup for SMS or voice verification.
  • Confirm the new number with a one-time code.

This is common with enterprise-style authentication systems where the phone number is part of a broader identity policy.

How to update the number in common WordPress security plugins

Although each plugin has its own interface, the underlying process is usually straightforward once you locate the correct settings screen.

Wordfence

Wordfence commonly uses two-factor authentication through an authenticator app, but some site owners also connect recovery contact details through their WordPress profile or related account settings.

To change a phone number used for recovery or alerts, check the user profile, the Wordfence login security section, and any connected Wordfence Central account.

miniOrange

miniOrange often supports multiple methods, including SMS, email, and authenticator apps.

If SMS is enabled, you can usually update the phone number in the miniOrange configuration area or reconfigure the method from your WordPress user account.

Save the changes and test a login immediately.

Duo Security

Duo Security typically manages authentication through the Duo account rather than WordPress core.

If a phone number changes, update it in the Duo administrative console or user directory, then sync the change back to the WordPress login flow.

This is especially important for organizations using centralized identity management.

Hosting provider login protection

Some managed WordPress hosts add their own security layer for administrator access.

In that case, the phone number may be stored in the hosting dashboard.

Check the host’s security or account settings, update the number there, and confirm whether WordPress admin login is tied to that account-level factor.

What if you are locked out of WordPress?

If you no longer have access to the old phone number, you may be unable to complete the regular login challenge.

In that situation, use recovery methods provided by the plugin or host.

  • Use backup recovery codes if you saved them.
  • Try an alternate method such as email verification or an authenticator app.
  • Use trusted devices if the system allows them.
  • Contact the site administrator, host, or plugin support if you are the account owner but cannot sign in.

If you are the site owner and no backup method exists, a developer may need to disable the two-factor plugin temporarily through the database or file system.

This should be done carefully because security settings can affect all admin accounts on the site.

How to change the number through the WordPress user profile

Some configurations store two-factor-related contact details in the standard WordPress user profile.

This is the simplest path when available.

  1. Log in to the WordPress dashboard.
  2. Open Users, then select your profile.
  3. Look for contact or security details added by your plugin.
  4. Replace the outdated phone number with the new one.
  5. Save the profile and verify the new number.

Because WordPress core does not include SMS two-factor authentication by default, these fields are usually added by a plugin.

If you do not see a phone number setting on the profile page, check the plugin’s own settings instead of the user screen.

Security checks after changing the number

After updating the phone number, test the full login process to make sure the new number works as expected.

A change that saves in the dashboard may still fail at login if verification was not completed.

  • Log out and log back in using the new number.
  • Confirm that SMS codes arrive promptly.
  • Verify that recovery codes still work.
  • Remove access from the old number if the plugin leaves it active.

If the old number remains available to an inactive device or outdated account, disable it to reduce account takeover risk.

Security best practice is to keep only the current verified number and a separate recovery method.

Best practices for WordPress two-factor phone updates

Changing a two-factor authentication phone number is a good time to improve account security.

The goal is not just to update contact details, but to make sure login protection stays reliable.

  • Use a dedicated admin phone number that is not shared.
  • Prefer authenticator apps or passkeys when your plugin supports them.
  • Store backup codes in a secure password manager.
  • Keep the account email current for recovery notices.
  • Review all administrator accounts after the change.

If the site supports modern authentication standards, consider moving away from SMS as the primary factor.

SMS can be useful for recovery, but authenticator apps and hardware security keys generally provide stronger protection against SIM swapping and phone number recycling.

When to ask for technical help

You may need help from a developer, managed WordPress host, or plugin support team if the phone number is embedded in a custom login workflow, single sign-on setup, or network-wide multisite configuration.

This is especially true for organizations using SAML, OAuth, or centralized directory services such as Okta, Azure Active Directory, or Google Workspace.

Ask for help if any of the following apply:

  • The site uses custom code for authentication.
  • You cannot find the number in the dashboard or plugin settings.
  • You are locked out and have no recovery codes.
  • The phone number is managed by an external identity provider.

With the right plugin or admin access, how to change two factor authentication phone number on WordPress is usually a quick update.

The key is knowing whether the number lives in WordPress itself, in a security plugin, or in an external account that controls login security.