← Back to Blog
WordPress Troubleshooting

Locked Out of WordPress? Fix the Login Loop

October 05, 2026 65 views Amanur Rahman
Stuck in a WordPress login redirect loop after an SSL or URL change? Learn the common causes and how to fix wp-admin lockouts, even without dashboard access.

You type your username and password, press Log In, and the page just reloads. No error, no dashboard, just the same login screen again. Or the browser gives up with a message that the page redirected you too many times. Either way, you are locked out of your own website.

This is the WordPress login redirect loop, and it is stressful because it often appears right after you did something sensible: installed an SSL certificate, moved the site, switched to www, or updated a plugin. The good news is that it is almost always fixable without losing any content, and the causes follow a clear pattern.

This guide covers the most common triggers in the order you should check them, with the exact steps to fix each one even when you cannot reach the dashboard.

Quick answer: the most common cause is a mismatch between the WordPress Address and Site Address, usually after an SSL, www, or domain change. Next come HTTPS redirect conflicts (especially Cloudflare's Flexible SSL), a damaged .htaccess file, cookie problems, and plugin, theme, or cache conflicts. Start by clearing cookies and testing a private window, then work down the list below.
Before you edit anything: take a backup of your files and database. Most fixes below involve editing wp-config.php, .htaccess, or the database, and a typing mistake can make things worse. Your host's control panel usually has a one-click backup.

What a Login Redirect Loop Actually Is

When you log in, WordPress checks your password, sets a login cookie in your browser, and sends you to the dashboard. The dashboard then checks for that cookie. If the cookie is missing, wrong, or set for a different address than the one you are visiting, WordPress decides you are not logged in and sends you back to the login page.

That is the loop. Anything that interferes with the cookie, or that keeps bouncing you between two versions of the same address, can cause it. Understanding this helps you diagnose it: nearly every cause below is either an address mismatch, a redirect conflict, or something blocking the cookie.

Quick Checks Before Touching Any Files

These take two minutes and solve a surprising share of cases.

  1. Clear cookies and cache for your site. Old or corrupted cookies are a classic trigger. Clear them for the site, not for everything.
  2. Try a private or incognito window. If you can log in there, the problem is stored in your normal browser.
  3. Try a different browser or device. This rules out extensions that interfere with cookies.
  4. Check that you are using the correct address. If your site works at www but you log in at the non-www version, the cookie may not carry across.
  5. Disable browser extensions such as privacy or ad blockers for this site.

If none of that helps, move on to the causes below.

Cause 1: Mismatched WordPress Address and Site Address

This is the single most common cause. WordPress stores two addresses: the WordPress Address (where the core files live) and the Site Address (what visitors type). If they differ, for example one uses http and the other https, or one has www and the other does not, the login cookie can fail and cause a loop.

How to check and fix it from the dashboard

If you can still reach Settings, General through any route, make sure both addresses are identical and use the correct https and www format. Save and test again.

How to fix it from wp-config.php when locked out

You can force both addresses by adding two lines to wp-config.php, above the line that says to stop editing:

define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );

Replace example.com with your real domain, using exactly the address you want visitors to use. Upload the file, then try logging in. Once you are in, set the correct values in Settings, General and remove these lines, since they override the dashboard fields.

How to fix it in the database

If editing the file does not help, the values can be corrected directly in the database using phpMyAdmin from your hosting panel. Open the options table (the prefix may not be wp_ on your site) and update the two rows named siteurl and home:

UPDATE wp_options
SET option_value = 'https://example.com'
WHERE option_name IN ('siteurl', 'home');

Again, back up first and use your own domain and table prefix. This cause is especially common after a domain change or a move to a new host. If you are planning or have just completed one, our guide to WordPress website migration cost and what to expect explains where these problems usually appear.

Padlock with keys on a colorful surface, representing being locked out of a WordPress admin area

Cause 2: HTTPS and SSL Redirect Conflicts

Adding an SSL certificate is a common moment for login loops to start. The site is now served over HTTPS, but something is still sending visitors back to HTTP, or two different systems are both trying to force the redirect.

Cloudflare Flexible SSL

If you use Cloudflare, check the SSL/TLS mode. With the Flexible option, Cloudflare talks to your visitors over HTTPS but to your server over HTTP. If your server or a plugin then forces HTTPS, the two keep redirecting each other and the browser reports too many redirects. Switching to Full, or Full (strict) with a valid certificate on your server, usually ends the loop.

Servers behind a proxy or load balancer

On some hosts, WordPress cannot tell that the original request was secure, because SSL is handled before the request reaches it. The fix is to tell WordPress to trust the forwarded header. Add this to wp-config.php above the "stop editing" line:

if ( isset( $_SERVER['HTTP_X_FORWARDED_PROTO'] ) && $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https' ) {
    $_SERVER['HTTPS'] = 'on';
}

Only use this if your host or proxy sets that header. Your hosting provider's support can confirm.

Duplicate redirects

If a redirect plugin, an SSL plugin, your host's setting, and a rule in .htaccess are all forcing HTTPS, they can conflict. Pick one method and disable the others. Many hosts offer a "force HTTPS" toggle that makes the plugin and the manual rule unnecessary.

Admin over SSL

You can also require the admin area to always use HTTPS by adding this line to wp-config.php:

define( 'FORCE_SSL_ADMIN', true );

This only works properly when your site's HTTPS is already set up correctly. If you add it while HTTPS is misconfigured, it can make a loop worse.

Cause 3: A Damaged .htaccess File

On Apache and LiteSpeed servers, the .htaccess file in your site's root folder controls redirects and permalinks. A plugin, a manual edit, or a failed update can leave it with rules that conflict or loop.

How to test it

  1. Connect through FTP or your host's File Manager. Turn on the option to show hidden files, since .htaccess begins with a dot.
  2. Rename .htaccess to .htaccess-old.
  3. Try logging in again.

If you can log in, the file was the problem. Go to Settings, Permalinks and click Save to generate a fresh file. If the file is missing and you cannot get in, create a new .htaccess with the standard WordPress rules:

# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress

If you had custom redirect rules, copy them back one at a time from the old file and test after each. That is how you find the one that causes the loop. A damaged .htaccess also commonly causes server errors, which we cover in our guide to the WordPress 500 internal server error.

Cause 4: Cookie and Domain Problems

Because the loop is really a missing cookie, anything that blocks or misplaces the cookie can trigger it.

  • www and non-www mixed up. A cookie set for one version is not sent to the other. Choose one version, set it in both address fields, and redirect the other to it.
  • A custom cookie domain. If someone added a COOKIE_DOMAIN line to wp-config.php and it no longer matches your domain, logins fail. Remove or correct it.
  • Stray whitespace in files. Extra spaces or blank lines before the opening PHP tag or after a closing tag in wp-config.php or the theme's functions.php can send output too early, which stops cookies from being set. Remove any characters outside the PHP tags.
  • Browser or privacy settings. Cookies blocked for the site, or aggressive tracking protection, can prevent the login cookie from being stored.

Cause 5: Plugin and Theme Conflicts

A plugin that handles redirects, security, caching, membership, or login pages can break the login flow, especially right after an update. A theme with faulty code in functions.php can do the same.

How to deactivate plugins without dashboard access

  1. In FTP or File Manager, open the wp-content folder.
  2. Rename the plugins folder to plugins-old. This deactivates every plugin at once.
  3. Try logging in.

If you can now log in, rename the folder back to plugins, then deactivate plugins one at a time from the dashboard and test after each to find the culprit. Alternatively, rename individual plugin folders inside plugins one by one.

How to test the theme

Rename your active theme's folder inside wp-content/themes. WordPress falls back to a default theme if one is installed. If login works, the theme is the cause. For a complete method, see our guide on diagnosing and fixing WordPress plugin conflicts.

Cause 6: Caching and Security Plugins

Caching

If your login page or admin area is being cached, WordPress may serve you a stale page that ignores your new login. Make sure wp-login.php and the wp-admin folder are excluded from page caching, and clear all cache layers: plugin, host, and CDN.

Security and login plugins

Plugins that change the login URL, add two-factor authentication, limit login attempts, or run a firewall can all interfere. Symptoms include being redirected to a "not found" page, being locked out after a few tries, or a login that works for some users and not others. Check whether the plugin's settings changed recently, and whether your own IP address has been blocked. If you rely on these tools, our guide to WordPress security best practices explains how to use them without locking yourself out.

When the Redirect Is Not Yours

A normal login loop keeps you on your own site. If you are being sent to a different website entirely, or you see unfamiliar admin users, strange files, or spam pages, the cause may be malware rather than a setting. Some malware plants redirect code in files or the database.

In that case, stop changing settings and treat it as a security incident. Our guide on recovering a hacked WordPress site covers the safe order of steps.

Step-by-Step Checklist

Work through these in order. Most login loops are solved by step 4.

  1. Take a backup of files and database from your host.
  2. Clear cookies and test a private window and a second browser.
  3. Confirm you are using the correct address, including https and www.
  4. Force the addresses with WP_HOME and WP_SITEURL in wp-config.php, or correct them in the database.
  5. Check SSL settings. Look at Cloudflare's SSL mode and remove duplicate HTTPS redirects.
  6. Rename .htaccess and test, then regenerate it from Permalinks.
  7. Rename the plugins folder to deactivate all plugins, then test.
  8. Rename the active theme folder to test with a default theme.
  9. Exclude login and admin pages from caching and clear all caches.
  10. Review security and login plugins, including any IP blocks.
  11. Check for signs of a hack if redirects go to another site.
  12. Remove temporary lines such as WP_HOME and WP_SITEURL once the real settings are correct.

Fix It Yourself or Hire Help?

Many login loops are a ten-minute job once you know where to look. Others are not worth risking on a live business site. Use this as a guide.

SituationReasonable to try yourself?
Loop started after clearing nothing, and a private window worksYes. Clear cookies and check extensions
You changed to https or www and then got locked outYes, if you are comfortable editing wp-config.php with a backup
Cloudflare or a proxy is involved and you are unsure of the SSL modeMaybe. A wrong change can take the site offline
You have no FTP or File Manager accessAsk your host first, or get help
You are being redirected to another site or see unknown admin usersNo. Treat it as a security issue and get help
It is a WooCommerce store taking ordersBe cautious. Every hour offline costs sales
You have tried all the steps and still cannot log inTime for a developer

A developer can usually find the cause in a fraction of the time, because they know which of these causes to rule out first and how to test without taking your site offline. If you want help, you can hire a WordPress developer to diagnose and fix it.

Locked out of your WordPress admin?

I fix login loops, redirect problems, and SSL conflicts for site owners, carefully and with a backup first so nothing is lost. Message me the exact symptom and what changed just before it started, and I will tell you the likely cause and what it will take to fix.

Chat on WhatsApp

How to Prevent It Next Time

  • Back up before any change. Especially before SSL changes, moves, or major updates. Our guide to WordPress maintenance costs explains what a good care plan includes, backups among them.
  • Test changes on a staging copy first when the site earns money.
  • Choose one canonical address (https, and www or non-www) and keep it consistent everywhere.
  • Use one method for forcing HTTPS, not several.
  • Exclude login and admin pages from caching.
  • Update plugins in small batches, so a problem is easy to trace.
  • Keep a second admin account and know your host's File Manager, so you have a way in when something breaks.

Frequently Asked Questions

Why does WordPress keep redirecting me back to the login page?

WordPress sets a login cookie when you sign in and then checks for it on the dashboard. If the cookie is missing, blocked, or set for a different address, WordPress sends you back to the login page. Address mismatches, HTTPS conflicts, and plugin or cache problems are the usual causes.

How do I fix a WordPress login loop without dashboard access?

Use FTP or your host's File Manager. You can add WP_HOME and WP_SITEURL lines to wp-config.php, rename the .htaccess file, or rename the plugins folder to deactivate all plugins. Each of these works without logging in.

Why did the login loop start after I installed SSL?

Usually the site address still uses http while the site is served over https, or two systems are both forcing the redirect. Cloudflare's Flexible SSL mode combined with a server-side HTTPS redirect is a common cause. Match the addresses and keep only one redirect method.

Will fixing the login loop delete my content?

No. The loop affects access, not your posts, pages, or media. Still, back up files and the database before editing anything, because a typing mistake in a configuration file can cause new problems.

What does "too many redirects" mean in WordPress?

It means the browser was sent in a circle between two or more addresses until it gave up. It is the same family of problem as a login loop and is usually fixed by correcting the site addresses, SSL settings, or conflicting redirect rules.

Can a plugin cause the WordPress login to loop?

Yes. Security, caching, redirect, membership, and login-page plugins are the most common. Rename the plugins folder through FTP to deactivate them all, then reactivate them one by one to find the one responsible.

When should I hire a developer for a login problem?

Get help if you have no file access, if the problem involves Cloudflare or server-level SSL settings, if you see redirects to other websites or unknown admin users, or if you have tried the steps and still cannot log in. For a store taking orders, speed matters, so getting help early is often cheaper than waiting.

A login redirect loop feels like a disaster, but it is almost always a configuration problem rather than lost data. Start with cookies and a private window, check your addresses and SSL settings, then test .htaccess, plugins, and caching in that order. If the steps do not solve it, or the site is too important to experiment on, contact me and I will help you get back in safely.

Tags: WordPress Login Redirect Loop WordPress Login Problem wp-admin Locked Out WordPress SSL Redirect WordPress Troubleshooting WordPress Too Many Redirects
Explore more: Services · Hire a WooCommerce Developer · Portfolio · Contact

Need Help with Your WordPress Project?

Let's discuss how I can help you build something amazing!

Get in Touch →
← Back to Blog