Can't Log In to WordPress? How to Fix Common Login Problems
Fix WordPress login problems step by step: redirect loops, cookie errors, forgotten passwords, missing reset emails, locked-out accounts and security plugins that block you.

Table of Contents
- Symptom 1: "The password you entered is incorrect"
- Symptom 2: You log in and land back on the login page (redirect loop)
- Symptom 3: "Cookies are blocked or not supported by your browser"
- Symptom 4: Locked out after too many attempts
- Symptom 5: A 403 Forbidden or blank page on wp-admin
- Symptom 6: Two-factor authentication code not accepted
- If you suspect the account was taken over
- Quick diagnosis table
- Using WP-CLI to regain access
- Prevent login problems
- Frequently Asked Questions
- Related reading
- Sources
Most WordPress login problems fall into a few groups: the password is wrong or the reset email never arrives, a redirect loop sends you back to the login page, cookies are blocked, or a security plugin or firewall has locked you out. Identify which one you have from the symptom, then use the matching fix below.
Symptom 1: "The password you entered is incorrect"
- Use Lost your password? on the login page to get a reset link.
- Check spam folders. If the email never arrives, the site's outgoing email is probably not working; see the next section.
- Make sure you are using the right username or email address; administrators sometimes have more than one account.
When the reset email never arrives
You can set a new password directly:
- In phpMyAdmin: open the
wp_userstable (the prefix may differ), edit your user, setuser_passto a new password and choose the MD5 function. WordPress upgrades the hash to its stronger format the next time you log in. Use a strong password and change it again from your profile afterwards. - With WP-CLI (if SSH is available):
wp user update youruser --user_pass='new-strong-password'.
Then fix email delivery so it does not happen again: configure authenticated SMTP and the domain's SPF and DKIM records. See SPF, DKIM and DMARC explained.
Symptom 2: You log in and land back on the login page (redirect loop)
Common causes and fixes:
- Wrong site URLs. If the WordPress Address and Site Address differ from the URL you use (http vs https, www vs non-www), login cookies are set for the wrong address. Fix them in
wp-config.php:
define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );
- HTTPS behind a proxy or CDN. If the site is behind Cloudflare or a load balancer, WordPress may not detect HTTPS and loop between http and https. Make sure SSL is set correctly end to end (for example Full or Full (strict) mode in Cloudflare) and see how to force HTTPS and fix mixed content.
- Caching the login page.
wp-login.phpand/wp-admin/must never be cached. Exclude them in your cache plugin or server cache. - A plugin redirect. Rename
wp-content/pluginstemporarily to test; see how to fix the WordPress white screen of death for the method.
Symptom 3: "Cookies are blocked or not supported by your browser"
- Make sure the browser allows cookies for the site.
- Clear cookies for the domain and try a private window.
- Check the site URLs as above; a mismatch often triggers this message.
- Look for stray output (a blank line or spaces) before
<?phpinwp-config.phporfunctions.php, which can stop WordPress setting cookies. The error log shows "headers already sent" in that case.
Symptom 4: Locked out after too many attempts
Login-protection plugins block an IP address after repeated failures.
- Wait for the lockout period, or try from a different network.
- If you are locked out permanently, rename the security plugin's folder in
wp-content/plugins/to disable it, log in, then rename it back and whitelist your IP if appropriate. - Your host's firewall may also have blocked your IP. Contact support with your IP address.
Symptom 5: A 403 Forbidden or blank page on wp-admin
A web application firewall rule, .htaccess restriction or file-permission problem can block /wp-admin/. See common hosting errors: 500, 503, 508 and 403.
Symptom 6: Two-factor authentication code not accepted
- Check your phone's time is set automatically; authenticator codes depend on accurate time.
- Use one of your saved backup or recovery codes.
- As a last resort, disable the 2FA plugin by renaming its folder, log in, and set it up again.
If you suspect the account was taken over
If your password stopped working without you changing it, or you see users you did not create, treat it as a security incident: reset all passwords, regenerate the salts in wp-config.php to log everyone out, and check for malware. See how to clean a hacked WordPress site.
Quick diagnosis table
| What you see | Most likely cause | Go to |
|---|---|---|
| "Password incorrect", reset email never arrives | Broken outgoing email | Symptom 1 |
| Login form reloads after entering correct details | Site URL mismatch, cached login page | Symptom 2 |
| "Cookies are blocked" | Cookie settings, URL mismatch, stray output | Symptom 3 |
| "Too many attempts" or a block page | Login protection or host firewall | Symptom 4 |
| 403 Forbidden on wp-admin | Firewall rule or .htaccess |
Symptom 5 |
| Code from the authenticator app rejected | Phone time wrong, wrong account | Symptom 6 |
Using WP-CLI to regain access
If you have SSH access, WP-CLI can fix most lockouts without touching the database by hand:
wp user list --role=administrator # find the right account
wp user update 1 --user_pass='new-long-password'
wp plugin deactivate some-security-plugin # if a plugin is blocking logins
wp option get siteurl && wp option get home
Reactivate any plugin you disabled once you are back in, and fix its settings so the lockout does not recur.
Prevent login problems
- Keep the admin email address current and make sure the site can send email.
- Store passwords and 2FA backup codes in a password manager.
- Never cache login and admin pages.
- Keep site URLs consistent (one canonical domain, HTTPS).
Frequently Asked Questions
Can I change the WordPress login URL?
Yes, with a plugin. It reduces automated noise but is not a substitute for strong passwords, 2FA and login limiting.
Is it safe to reset the password in phpMyAdmin?
Yes, if you change it again from your profile afterwards. Only do it on your own site, with a strong password.
Related reading
Protect the login properly with the WordPress security checklist. The WordPress overview is in WordPress hosting: what it is and how to choose. If your host's firewall has blocked you, contact ServerNeed support.
Sources
Featured image: “Password Please” by okubax, licensed under CC BY 2.0.
Last updated 7 October 2026



