Home›Insights›WordPress Login Not Working: How to Get Back Into wp-admin
WordPress

WordPress Login Not Working: How to Get Back Into wp-admin

Locked out of WordPress? This guide covers the real reasons a WordPress login fails: wrong password, a redirect loop, a mismatched site URL, a security plugin lockout, or a changed login address, and how to get back into wp-admin without the dashboard.

I
Inspirable Editorial•7 min read

When the WordPress login is not working, the cause is one of a handful of things: a wrong or forgotten password, a login page that keeps reloading because of a site URL or cookie mismatch, a security or login plugin blocking access, or a login address that has been changed. You do not need to get into the dashboard to fix any of them. Each can be corrected from the hosting file manager, the database, or the command line, and the first step is working out which one you have.

When you cannot reach the dashboard, you do not need the dashboard. Almost every login problem can be fixed from the files or the database.
Site down or broken right now?
Talk to a USA-based WordPress support team. Call and we will start on it.
Call 844-455-2800Send us a message

First, work out which kind of login problem it is

The symptom tells you the cause. If you see Error: The password you entered is incorrect, it is credentials. If you submit the form and land back on the login page with no message, or you get stuck in a loop between wp-login.php and wp-admin, it is a URL or cookie problem. If you see a message that you have been locked out or too many attempts, a security plugin or your host is blocking you. If wp-login.php shows a 404 or a blank page, the login address or a core file is the issue. Take a moment to note exactly which of these you see, and whether anything changed first, such as a migration, a switch to https, or a new plugin.

Wrong password or no reset email

For a wrong password, use the Lost your password link on the login page, which emails a reset link to the account's email address. If the email does not arrive, check spam, and confirm that your site can send mail at all, since many do not. You can bypass email entirely: in your hosting panel open phpMyAdmin, find the users table, which is wp_users unless you use a different prefix, edit your user row, and set user_pass to a new password with the function dropdown set to MD5. WordPress accepts that and upgrades the hash the next time you log in. If you have command line access, the same result comes from the WP-CLI command wp user update followed by your username and the option --user_pass with a new password.

The login page reloads or loops

A login page that reloads, or a loop between wp-login.php and wp-admin, is usually a mismatch between the site URL settings and how you reach the site, for example the site is set to http but loaded over https, or www and non-www do not match. In wp-config.php you can force the correct values by adding define( 'WP_HOME', 'https://yourdomain.com' ); and define( 'WP_SITEURL', 'https://yourdomain.com' ); using your real address, which overrides the database settings. Also try the login in a private window, or clear cookies for the domain, since a stale or blocked cookie produces the same loop. Make sure your browser accepts cookies and that your host or a caching layer is not caching the login page.

A plugin is blocking you

If a plugin is blocking you, such as a security, two-factor, or login-limit plugin, deactivate it from the files. Rename the plugin's folder in wp-content/plugins, adding -off to the name, and try the login again. If you do not know which plugin, rename the whole plugins folder to plugins-off, log in, rename it back, and reactivate plugins one at a time. A plugin that limits login attempts may also have locked your IP address; deactivating it clears that, and you should then check its settings before turning it back on. If your host runs its own brute-force protection, ask them to unblock your IP.

wp-login.php is missing or the login address changed

If wp-login.php returns a 404 or a blank page, check whether a plugin has moved the login address, which some security plugins do deliberately to reduce attacks. Deactivating that plugin from the files, as above, restores the standard address. If the page is blank rather than missing, it may be a fatal error, and our guides on the white screen of death and the critical error explain how to find it. If core files were damaged by a failed update, re-uploading fresh copies of the wp-admin and wp-includes folders from wordpress.org, leaving wp-content alone, repairs them.

If you do not recognize the admin account

If you get back in and see administrator accounts you do not recognize, treat it as a security incident, not a login problem. Unfamiliar admin users, a password that changed without you changing it, or a login that stopped working at the same time as other odd behavior are signs the site may have been compromised. Change every password, remove accounts you did not create, and follow the steps in our guide on what to do when your WordPress site is hacked. Enabling two-factor authentication and limiting login attempts, with a reputable plugin configured correctly, prevents most account takeovers.

Get back into your WordPress admin

If you would rather not troubleshoot the login problem yourself, or the steps above did not clear it, Inspirable's USA-based team can take it from here. Call 844-455-2800 or contact us and we will find the cause, restore the site, and explain what happened in plain language. See our WordPress support services for how emergency fixes and monthly support work. A WordPress care plan from $49.99 a month, with encrypted backups every 5 hours and managed updates, is what prevents most of these errors in the first place.
Call 844-455-2800Send us a message

Frequently asked questions

I
Inspirable Editorial
Enterprise WordPress development since 2012