Why can't I log in to WordPress admin?

Can't log in to your WordPress dashboard? Learn the common causes, from lost passwords to redirect loops and lockouts, and what you can safely check first.

Open a support ticket

Being unable to log in to the WordPress dashboard is frustrating, especially when you need to publish something, process an order or change a setting quickly.

The good news is that, in most cases, the website itself is fine. Visitors can still see it, and your content is still there. What has stopped working is the way you get into the admin area.

The causes vary a lot. You may simply have forgotten the password and not received the reset email. The login page may keep sending you back to itself. A security plugin may have locked you out, or the login address may have been changed. Less often, your account may have been removed or downgraded, which can be a sign that someone else got into the website.

This guide explains how to recognize each situation, what you can safely try and when it is better to ask for support.

What exactly happens when you try to log in?

The first step is to describe precisely what you see. Different symptoms point to different causes.

  • You get "incorrect password" or "unknown username": the details you are using do not match an account on the website.
  • The login page reloads and asks for your details again: this is a redirect loop, often linked to cookies, the website address or HTTPS.
  • You see a message about too many attempts, or your access is blocked: a security plugin or firewall has probably locked you out.
  • You are asked for a code you cannot provide: two-factor authentication is active and you no longer have the device or the codes.
  • The login page shows "page not found": the login address may have been changed.
  • You log in but see a limited dashboard or a message that you are not allowed to access a page: your account role may have changed.
  • You see "There has been a critical error" after logging in: a plugin or theme is failing in the admin area.

Write down the exact message, or take a screenshot. It will be useful whatever the cause.

Have you forgotten your password?

This is the most common situation and usually the easiest to solve.

On the login page, click Lost your password? and enter your username or email address. WordPress sends a link to the email address registered for your account.

The reset email does not arrive

If the email does not arrive within a few minutes:

  • check the spam and junk folders
  • make sure you used the email address actually registered on the website, which may be an old or shared address
  • ask a colleague who is also an administrator to check your account email in Users → All Users

Many websites have trouble sending email because WordPress, by default, relies on the server's basic mail function, which some email providers treat as suspicious. If other emails from the website, such as form notifications or order confirmations, are also not arriving, this may be the cause. An SMTP plugin or a transactional email service usually solves it, but it needs to be configured by someone with access.

If another administrator can log in, the simplest solution is often for them to send you a password reset from your user profile, or to check that your email address is correct.

Does the login page keep reloading?

If you enter the correct details and the login page simply appears again, you are probably in a login loop. Common causes include:

Cookies

WordPress uses cookies to remember that you are logged in. If your browser blocks them, or an old cookie is causing a conflict, the login does not stick.

Try:

  • a private or incognito window
  • another browser
  • clearing cookies for the website only

If WordPress shows a message saying cookies are blocked or not supported, this is very likely the cause.

The website address settings

WordPress stores two addresses: the WordPress Address and the Site Address. If they do not match how the website is actually reached, for example http instead of https, or with and without www, the login cookie may be set for the wrong address and you end up in a loop.

This often happens after:

  • a migration to a new domain or server
  • switching the website to HTTPS
  • a change in the domain configuration

HTTPS and proxy configuration

If the website sits behind a CDN or proxy such as Cloudflare, or the hosting provider handles HTTPS in a special way, WordPress may not correctly detect that the connection is secure. This can cause redirects between http and https that never end.

Caching of the login page

A caching plugin, server cache or CDN that caches the login page or the admin area can also cause strange login behavior. The login and admin pages should normally be excluded from caching.

Has a security plugin locked you out?

Security plugins often limit login attempts. After several wrong passwords, they block the user or the IP address for a period of time. Some show a clear message, others simply refuse the login.

Possible situations:

  • you, or someone in your office sharing the same internet connection, entered the wrong password too many times
  • your IP address was blocked by a firewall rule
  • the plugin requires a captcha that is not loading
  • two-factor authentication is active and you have lost your phone or codes

What you can try:

  • wait for the lockout period to end, if the message mentions one
  • try from a different network, such as mobile data, only to confirm whether your IP is blocked
  • look for the recovery codes you saved when you set up two-factor authentication
  • ask another administrator to unblock you or reset your two-factor settings

If none of this works, someone with access to the website files or the hosting panel can temporarily disable the security plugin. This should be done carefully and the plugin re-enabled as soon as possible.

Has the login address been changed?

By default, the WordPress login page is at /wp-login.php or /wp-admin/. Some security plugins let you change it to a custom address, to reduce automated attacks.

If the usual address shows "page not found", check:

  • old emails or notes from whoever set up the website
  • your password manager, which may have saved the custom address
  • the documentation from your agency or developer

If nobody knows the address, it can be restored by someone with file access, as described in the hands-on section.

Has your account been deleted or its role changed?

If WordPress says your username does not exist, or you log in but can no longer see settings, plugins or users, your account may have been deleted or its role lowered.

There can be ordinary explanations, for example a colleague cleaning up old accounts or changing permissions.

But if nobody in your team made that change, treat it as a possible security incident. Attackers who get into a website sometimes create their own administrator account and remove or downgrade the real ones. Look for other signs, such as unknown users, unexpected content or redirects, and read our guide on unknown WordPress admin users. If you suspect a compromise, the guide on what to do if WordPress has been hacked explains the next steps.

In that case, regaining access is only the first step. The website should also be checked for whatever allowed the change.

Do you see a critical error when logging in?

If the login works but the dashboard then shows "There has been a critical error on this website", the problem is not your account. A plugin, theme or piece of code is failing in the admin area. Our guide on the WordPress critical error explains what to check.

What should you avoid doing?

Avoid:

  • trying the password many times in a row, which can trigger or extend a lockout
  • sharing your password or a colleague's by email or chat
  • creating new administrator accounts as a workaround without telling anyone
  • deleting security plugins instead of temporarily disabling them
  • editing the database directly to change passwords or roles
  • ignoring a deleted or downgraded account when nobody can explain it

When should you ask for technical support?

Ask for help when:

  • the reset email never arrives and no other administrator can help
  • you are stuck in a login loop after a migration or an HTTPS change
  • a security plugin has locked out every administrator
  • you have lost your two-factor device and recovery codes
  • nobody knows the custom login address
  • your account was deleted or downgraded and nobody knows why
  • you notice unknown users, strange content or redirects
  • you are not comfortable working with files, SSH or WP-CLI

You do not need to know the cause in advance. Describing what happens when you try to log in is enough to start.

What information should you collect?

Useful details include:

  • the website URL and the login address you use
  • the exact message you see, or a screenshot
  • when the problem started
  • what changed recently, such as a migration, an HTTPS change or a new plugin
  • whether other administrators can log in
  • which security plugin is installed, if you know
  • whether you use a CDN or proxy such as Cloudflare
  • whether you noticed anything unusual on the website

Do not send passwords by ordinary email. D4Hub can explain what access is needed and how to share it securely.

How D4Hub can help

The goal is to get you back in safely and make sure the lockout is not hiding a bigger problem.

Depending on the situation, D4Hub can help with:

  • restoring access to an administrator account
  • fixing email delivery so password resets and notifications arrive
  • correcting the website address settings after a migration or an HTTPS change
  • resolving redirect loops involving caches, CDNs or proxies
  • safely unlocking or reconfiguring security plugins and two-factor authentication
  • recovering or resetting a custom login address
  • checking users and roles for signs of unauthorized access
  • investigating and cleaning the website if a compromise is suspected

You can ask for support at any stage, whether you have just been locked out or have already tried several fixes.

Open a support ticket

For hands-on users: regaining access with WP-CLI and file access

These steps are for people comfortable with SSH, WP-CLI and SFTP or a hosting file manager.

Before changing anything, back up the website files and the database. Make sure you are working on the right WordPress installation, especially if the hosting account contains several websites.

List the users and their roles

wp user list

To see only administrators:

wp user list --role=administrator

Check that your account exists, that its email address is correct and that its role is what you expect. Also look for administrators you do not recognize. If you find any, do not delete them immediately: note their details first and read our guide on unknown WordPress admin users.

Reset a password

You can set a new password for a user by ID:

wp user update 1 --user_pass='a-new-strong-password'

Replace 1 with the ID from wp user list.

Be careful: a password typed in a command is usually saved in your shell history, and may be visible to other users of the same server. After using it, remove the line from your history or change the password again from the dashboard once you can log in. Alternatively, WP-CLI can send a standard password reset email instead:

wp user reset-password 1

This only helps if the website can send email correctly.

If the role was lowered and you are certain the account is legitimate, the role can be restored:

wp user set-role 1 administrator

If the account was changed without explanation, investigate before restoring it.

Check the website addresses

For a login loop, check the two addresses WordPress uses:

wp option get siteurl
wp option get home

Both should normally match the address visitors use, including https and www if applicable. If one is wrong, it can be updated:

wp option update siteurl 'https://example.com'
wp option update home 'https://example.com'

Also open wp-config.php and check for WP_HOME or WP_SITEURL lines. If they are present, they override the database values, so a change made with WP-CLI will have no effect until those lines are corrected too.

Disable a security plugin by renaming its folder

If a security plugin has locked you out:

  1. Connect through SFTP or the hosting file manager.
  2. Open wp-content/plugins/.
  3. Find the folder of the security plugin.
  4. Rename it, for example from plugin-name to plugin-name-disabled.
  5. Try to log in again.

The same approach restores the default login address if a plugin changed it, and turns off two-factor authentication handled by that plugin.

Some security plugins also add rules at server level, for example in .htaccess or in a firewall file loaded before WordPress. These may keep working even when the plugin folder is renamed. If you are still blocked, check with the plugin documentation or ask for help.

Once you are back in, rename the folder to its original name, reactivate the plugin from the dashboard, review its settings and unblock your IP address or reset your two-factor setup. Do not leave the website without protection.

Check for errors when logging in

If the dashboard shows a critical error after login, enable the WordPress debug log as described in our guide on the WordPress critical error and look at wp-content/debug.log for the plugin or theme involved.

D4Hub can help you read the results and decide the safest next step.

FAQFrequently asked questions

Usually not. In most cases the public website keeps working and only the admin area is affected. Check the website in a private window to confirm.

Often because the website cannot send email reliably, or because the email goes to an old or unexpected address. Check your spam folder and whether other website emails arrive. An SMTP setup usually fixes delivery problems.

This is usually a cookie problem, a mismatch in the website address settings, or an HTTPS or proxy configuration issue. It often appears after a migration or after switching to HTTPS.

Look for the recovery codes you saved when setting up two-factor authentication, or ask another administrator to reset it for you. If neither is possible, someone with file or WP-CLI access can temporarily disable the plugin that manages it.

Temporarily, yes, if you do it to regain access and re-enable it straight away. Do not leave the website without protection, and review the plugin settings once you are back in.

If nobody in your team removed it, treat it as a possible compromise. Check the list of users for unknown administrators and look for other unusual signs. Regaining access is the first step, but the website should also be checked.

Yes. With access to the hosting account or the website files, D4Hub can restore access, check the users and find out why the lockout happened.