WordPress Admin Login Not Working? Common Causes and Fixes
Locked out of WordPress admin? Try these practical fixes for password, cookie, plugin, redirect, and security-related login problems.

Locked out of your own dashboard. The site still works for visitors, but you can't get in. Most login problems come down to stale cookies, a renamed login URL, a password mismatch, or a security plugin block. Here's the short fix list.
Fix 1: Check the Login URL
The default login URLs are:
example.com/wp-admin/
example.com/wp-login.php
If both return a 404, a security plugin has hidden the login URL. Check these common culprits:
- WPS Hide Login
- iThemes Security
- Wordfence (Login Security module)
Check your password manager or old emails for a custom login URL like example.com/my-secret-login/. If you can't find it, connect via SFTP, go to /wp-content/plugins/, and rename the security plugin folder. That restores the default login URL.
Fix 2: Reset the Password
Click Lost your password? on the login screen. Enter your username or email. Check inbox and spam for the reset link.
If the email never arrives, reset the password directly.
Via WP-CLI:
wp user update YOUR_USERNAME --user_pass="NEW_STRONG_PASSWORD"
Via phpMyAdmin:
- Open phpMyAdmin from your hosting panel.
- Select your WordPress database.
- Open the
wp_userstable. - Click Edit next to your admin username.
- In the
user_passfield, change the function dropdown to MD5, type the new password, click Go.
Fix 3: Clear Cookies and Test in a Private Window
Corrupted cookies cause login loops. Open an incognito or private window and try again.
If you can log in there, your normal browser is holding a bad cookie. Clear cookies and cache for your domain in the browser settings. Restart the browser. Try again.
Fix 4: Fix the Login Loop (URL Mismatch)
Login loop means you enter the correct password, the page reloads, and you're back at the login screen. This happens when WordPress Address (URL) and Site Address (URL) don't match—often after an HTTPS migration.
Fix it without dashboard access. Open wp-config.php via SFTP and add these lines near the top:
define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );
Replace with your exact domain. Match the protocol (http vs https) and the www vs non-www exactly.
Fix 5: Disable Plugins via SFTP
A broken security plugin, caching plugin, or failed update can block login. Disable all plugins externally:
- Connect via SFTP or hosting file manager.
- Go to
/wp-content/. - Rename
pluginstoplugins-disabled. - Try logging in.
- If it works, rename the folder back and reactivate plugins one at a time to find the culprit.
Fix 6: Check for an IP Block
Too many failed login attempts can trigger a firewall block. Wordfence, Cloudflare, and host-level WAFs all do this.
- Turn your VPN off, or turn one on to change your IP.
- Log into Cloudflare or your hosting panel. Check security logs for blocked requests from your IP.
- Whitelist your IP in the security plugin or firewall.
Fix 7: Check File Permissions and Memory
If login returns a 500 error or a blank screen, check these:
- File permissions: Directories
755, files644. Particularlywp-login.php. - PHP memory: Add this to
wp-config.php:
define('WP_MEMORY_LIMIT', '256M');
After You Get Back In
Once you're logged in, do these four things:
- Go to Settings → General. Confirm the admin email is correct and receiving mail.
- Go to Users → All Users. Delete any admin accounts you don't recognize.
- Enable two-factor authentication on all admin accounts (Google Authenticator, 1Password, or your security plugin).
- Store SSH and hosting panel credentials in a password manager so you always have a fallback.
That's It
Most login failures come down to cookies, a renamed login URL, a password mismatch, or a security block. Work through the fixes in order. Change one thing at a time.
Share





