yourdomain.com and www.yourdomain.com are technically different addresses. Both should work, but one should be canonical and the other should redirect to it.
WHY IT MATTERS
Search engines may treat them as two sites, splitting your rankings. Login cookies set on one hostname are not read on the other, which is a common cause of login loops. Analytics data is split across both.
CHOOSING
It makes no practical difference which you pick. Non-www is shorter and more common now. Pick one and be consistent everywhere: your application's configured site address, your redirects, your sitemap, your marketing material.
SETTING IT UP
In WordPress, set both WordPress Address and Site Address in Settings > General to your chosen form.
Then add a redirect. In cPanel > Redirects, choose Permanent (301), select the domain, and redirect www to non-www, or the reverse.
Alternatively use .htaccess, but never both. Duplicate redirect rules cause loops.
TESTING
Visit both forms in a private browsing window and confirm that one redirects to the other, and that the padlock shows on both. AutoSSL covers both forms by default.