Skip to content

Locked out of WordPress admin: find which lockout you have and get back in

What the login screen shows tells you which lockout you have. A refused password, a missing reset email, a blocked address, a lost second step, a moved login page and a missing administrator account each have their own way back in. Find yours in the table, then follow that fix.

By
WP Ministry
Published

In short

  • Read the login screen before you change anything. The message, or the lack of one, names the lockout.
  • "The password you entered … is incorrect" means the account exists. "Is not registered on this site" means no account has that name.
  • With access to the server you can set a new password, switch a plugin off or create an administrator without logging in.
  • A security plugin switched off from outside keeps its settings. Its lockout can still be running when the plugin comes back, so clear it before you log out.
  • A password or an email address that changed without you, or an account that vanished, is not an ordinary lockout. Check for a break-in first.
  • Once you are in, add a second administrator account and save backup codes.

"Locked out" is a dozen different faults, and what you see on the login screen tells you which one you have. Find your row in the table below, then go to the section or the page it names. In every case your posts, pages and settings are where you left them.

Two things decide which fixes are open to you: whether WordPress can send you email, and whether you can reach the server, through SSH, SFTP or your host's file manager and database tool. If you have neither, your hosting company is the first call.

Which lockout do you have?

Go to your login page, usually https://example.com/wp-login.php, and try once. Then match what happened.

What you seeWhat it isWhere the fix is
"Error: The password you entered for the username name is incorrect." The same line names the email address if you typed that.The account exists. The password is wrong.Select "Lost your password?". If the email cannot reach you, reset the password without email, below.
"Error: The username name is not registered on this site. If you are unsure of your username, try your email address instead." or "Unknown email address. Check again or try your username."No account has that name or that address. It was mistyped, or the account is gone.Try the other one. If both fail, restore an administrator, below.
You asked for a reset and no email came, or you see "Error: The email could not be sent. Your site may not be correctly configured to send emails."The site cannot send mail, or the mail is going somewhere you do not look.When the reset email does not arrive, below.
The login page reloads with no message, or says "Cookies are blocked or not supported by your browser."The login is lost on the way: the browser is not keeping WordPress's cookie, or the site's addresses disagree.The login page keeps refreshing or redirecting
You get in, then land on the login screen again while you work.The cookie that proves your login stops passing its check.WordPress keeps logging you out
A blank page, or "There has been a critical error on this website." at /wp-admin/PHP stopped on an error, almost always in a plugin or the theme.The critical error, the white screen of death, and how to switch plugins off from outside
"403 Forbidden" at wp-login.phpSomething refused the request before WordPress looked at your password: a server rule, a security plugin or the host's firewall.403 Forbidden
A "Page not found" at wp-login.php, and /wp-admin/ no longer leads to a login formA plugin has moved the login page to another address.Find a moved login address, below
A message that there were too many failed attempts, or that your address is blockedA security plugin counted failed logins from your address and shut it out for a while.Get past a security plugin's lockout, below
The password is accepted, then a screen asks for a code you cannot giveTwo-factor login, and the phone or the codes are gone.Recover from a lost second factor, below
"Sorry, you are not allowed to access this page." after logging in, or you land on your profile with a short menuYou are logged in, and the account's role no longer reaches the dashboard screens.Sorry, you are not allowed to access this page, and restore an administrator, below
The browser says the page redirected too many timesTwo parts of the setup disagree about the site's address.ERR_TOO_MANY_REDIRECTS
"Error establishing a database connection"WordPress cannot open its database. Nobody can log in until it can.Error establishing a database connection
After you select Log In, the address bar shows another domain or an old addressThe login form posts to the WordPress Address in the site's settings, and that setting is wrong.The address fix on the login page keeps refreshing, and how to change your WordPress URL

A security plugin may replace WordPress's own messages with one that does not say which part was wrong. If your message is not in the table, paste it into the error decoder, which says what it means and what to do first.

Reset a password without email

Try the ordinary way first. On the login screen, select "Lost your password?" and enter your username or email address. WordPress emails a link to the address on that user account, and by default the link works for one day.

If that email cannot reach you, set the password from the server. WordPress's page on resetting a password lists several methods and says the one you use depends on the access you still have. Start with these two.

With WP-CLI

WP-CLI is the command line tool for WordPress, and how to use WP-CLI covers connecting over SSH. Run the commands from the folder that holds wp-config.php. --skip-plugins and --skip-themes keep the plugins and the theme from loading, so a broken plugin cannot stop the command. Must-use plugins are still loaded.

  1. Step 1: List the administrators

    This prints the login name and the email address of every administrator. If your account is not on the list, go to "Restore an administrator" below.

    bash
    wp user list --role=administrator --fields=ID,user_login,user_email --skip-plugins --skip-themes
  2. Step 2: Set a new password

    Name the account by its login, its email address or its ID. Keep the single quotes around the password. Without them the shell reads a $ and the letters after it as a variable and drops them, and the command can answer "Success" while the old password stays in place. The answer is "Success: Updated user" and the ID. --skip-email stops the notice WordPress would otherwise send to the account's address.

    bash
    wp user update your-login --user_pass='a-long-new-password' --skip-email --skip-plugins --skip-themes
  3. Step 3: Log in, then change the password once more

    Change it from your profile screen, so that the password typed on a command line is not the one left in use.

With a database tool

WordPress's page gives a method for phpMyAdmin, and warns you to use it at your own risk. Export the database from the tool first, to your own computer. Then open the table whose name ends in users and edit the row for your account: clear the user_pass field, type the new password, choose MD5 in the function menu beside it, and select "Go". This statement does the same from the SQL tab, with your own table name and the ID of your row:

sql
UPDATE wp_users SET user_pass = MD5('a-long-new-password') WHERE ID = 1;

WordPress still accepts a password stored this way, and stores it again in its current, stronger format the first time you log in with it.

If the only problem is that the account's email address is one you can no longer read, WordPress's documentation offers a shorter route: put your own address in user_email in that row, then use "Lost your password?".

How to take over a WordPress site when your web developer has disappeared goes through both methods step by step.

When the reset email does not arrive

What WordPress said after you asked narrows it down.

  • "Check your email for the confirmation link, then visit the login page." WordPress handed the message to the server's mail program and got no error back. That is not the same as delivered.
  • "The email could not be sent. Your site may not be correctly configured to send emails." The server did not take the message at all.

Check three things before you go further:

  • The spam folder. The subject is the site's name in square brackets, then "Password Reset".
  • Which address it went to. The link goes to the email address on the user account. That is separate from the Administration Email Address under Settings, then General, and it may be an old address of yours or a former colleague's.
  • How long ago you asked. A link older than a day has run out. Ask for a new one.

The short route is not to wait. Set a new password from the server, as above. Then fix the mail, because the recovery link WordPress sends after a critical error travels the same way. How to fix WordPress not sending email has a two-minute test and the fix.

Find a moved login address

When wp-login.php answers "Page not found", a plugin has moved the login page. Your account is untouched. Only the way to the form is missing.

Look first where the address may be saved: your password manager, your bookmarks, your browser's history, anyone else who logs in. After that it depends on the plugin. WPS Hide Login's listing says it keeps the address in an option named whl_page, in the options table, or in the sitemeta table on multisite. This prints it:

bash
wp option get whl_page --skip-plugins --skip-themes

Put the answer after your domain, as in https://example.com/the-answer/. If WP-CLI answers that the option does not exist, no address was saved under that name.

Failing that, switch the plugin off from outside, as in the next section. The same listing says that deactivating the plugin brings the site back to the state it was in before, and /wp-login.php answers again. How to change the WordPress login URL covers the other plugins that move the login page and what to do if the address is still refused.

Get past a security plugin's lockout

A plugin that limits login attempts counts failures from one address and then refuses that address for a set time. While the lockout runs, the right password is refused too. Limit Login Attempts Reloaded, for one, says "Too many failed login attempts." and how long to wait.

Start with what costs nothing.

  • Wait. The message may say how long.
  • Come from another address. The lockout is on your connection, not on your account. Limit Login Attempts Reloaded's listing suggests opening the site from your cell phone. Use mobile data, not the same Wi-Fi.
  • Use the plugin's own way out, if it has one. Kadence Security's listing describes Magic Links, which let you log in while your username is locked out, if the feature was turned on beforehand. Its documentation also gives a line for wp-config.php, define('ITSEC_DISABLE_MODULES', true);, which turns the plugin's features off until you remove the line.

If none of those works, switch the plugin off from outside.

  1. Step 1: Find the plugin's folder name

    Each plugin has a folder of its own in wp-content/plugins. With WP-CLI, this lists the active ones by that name.

    bash
    wp plugin list --status=active --field=name --skip-plugins --skip-themes
  2. Step 2: Switch it off

    Use the folder's name. The answer is a line that says the plugin was deactivated, then "Success". Without WP-CLI, open wp-content/plugins in your host's file manager or over SFTP and add -off to the folder's name. WordPress checks that a plugin's main file exists, and does not run one it cannot find.

    bash
    wp plugin deactivate plugin-folder-name --skip-plugins --skip-themes
  3. Step 3: Log in, and stay logged in

    If you renamed the folder, open the Plugins screen once. WordPress shows a notice that the plugin "has been deactivated due to an error: Plugin file does not exist." and takes it off its list of active plugins.

  4. Step 4: Put the plugin back and clear the lockout

    Rename the folder back if you renamed it, and select Activate under the plugin's name. The plugin kept its settings while it was off, and its record of your lockout with them, so do not log out yet. Go to its settings and release your address, or add it to the list of addresses that are always allowed. Limit Login Attempts Reloaded's listing gives the same order: log in, rename the folder back, then whitelist your IP.

While the plugin is off, none of its protection is running, so do all four steps in one sitting.

If you are refused with the plugin off, the block is not in WordPress. WordPress's guide to brute force attacks describes limits set on the server or at a CDN, which answer before WordPress runs. How to fix the 403 Forbidden error shows how to tell who is refusing you and what to send your host. How to deactivate plugins when you are locked out has the other ways to switch one off, including through the database.

Recover from a lost second factor

Work down this list and stop at the first step that is open to you. The commands and screen names are those of the Two Factor plugin.

  1. Step 1: Use a backup code

    Log in with your password. On the screen that asks for a code, switch to the backup method and enter one of the codes you saved when you set the second step up. The plugin calls them Recovery Codes, and each works once.

  2. Step 2: Ask another administrator

    They edit your account on the Users screen, clear every method under "Two-Factor Options" and save. You then log in with your password alone.

  3. Step 3: Clear your own account from the server

    The plugin has a command of its own. It asks you to confirm, then removes every method for that one user and leaves everyone else as they were. Do not add --skip-plugins here: the command belongs to the plugin and is not there without it.

    bash
    wp two-factor disable your-login
  4. Step 4: Switch the plugin off

    This is the last resort. Deactivate it from outside as in the section above. Its folder is two-factor. While it is off, every account on the site opens with a password alone. The plugin keeps each user's settings, so you are asked for a code again once it is back on.

With another plugin, look for its own switch before you turn the whole thing off. Kadence Security's documentation gives a line for wp-config.php, define('ITSEC_DISABLE_TWO_FACTOR', true);, which turns off two-factor login and leaves its other features running. Remove the line as soon as you are in.

Then set the second step up again on the new phone and generate new codes. How to set up two-factor authentication covers that, and how to finish the last-resort route on a site with one administrator.

Restore an administrator

Use this when WordPress says your username is not registered, or when you can log in and the dashboard menu is nearly empty. An Administrator has access to all the administration features of a site. Every other role is refused some of its screens.

  1. Step 1: List every account and its role

    Look for your own login name and for the word administrator in the last column.

    bash
    wp user list --fields=ID,user_login,user_email,roles --skip-plugins --skip-themes
  2. Step 2: If your account is there with a lower role, raise it

    The answer begins "Success: Added" and names the account, the site and the role. Reload the dashboard. You do not need to log in again.

    bash
    wp user set-role your-login administrator --skip-plugins --skip-themes
  3. Step 3: If your account is gone, create one

    Give a login name and an email address that no account on the site already uses, or WP-CLI stops and says which one is taken. With no password in the command, WP-CLI makes one up and prints it once, on a line that begins "Password:". Save it in your password manager.

    bash
    wp user create new-login you@example.com --role=administrator --skip-plugins --skip-themes

Without WP-CLI, another administrator can change your role on the Users screen, and the page for "Sorry, you are not allowed to access this page." shows how to set it in the database. An account that is gone altogether has to be created, so send your host the last command and ask them to run it.

An account does not lose its role or disappear on its own. Before you carry on, find out who changed it.

Rule out a break-in

These are not ordinary lockouts:

  • Your password stopped working and you did not change it. When a password is changed from the dashboard, WordPress emails a "Password Changed" notice to the account's address. Look for one you did not cause.
  • The email address on your account changed. WordPress sends an "Email Changed" notice to the old address.
  • The site's Administration Email Address changed. WordPress sends an "Admin Email Changed" notice to the old address.
  • Your account is gone, is no longer an administrator, or the list shows an administrator nobody can name.

WordPress's documentation counts behavior that nobody authorized, such as the creation of new users, among the clear signs of a hack, and notes that there are times when a bad actor will hijack an administrator account.

Ask first. Another administrator, your developer or your host may have made the change, and one message settles it.

If nobody did, getting back in is not the fix. Whoever changed the account had a way in, and a new password does not close it. Do not delete what you find. Follow the runbook for the first hour, then how to check whether your site has been hacked and what an unknown admin user means and how to remove it properly. WordPress's documentation says to change the passwords again once the site is clean.

Once you are back in

Fix what locked you out, then make the next lockout a short one.

  • Close the cause. Put your address on the security plugin's allow list, repair the mail, set up the second step on the new phone, or save the moved login address in your password manager.
  • Add a second administrator account. Go to Users, then Add User, and choose the Administrator role. Give it a different email address from the first, a long password of its own and its own second step. With two, one can let the other back in.
  • Save backup codes for every administrator, somewhere other than the phone that holds the authenticator app.
  • Check both email addresses. The one on your profile receives password resets. The Administration Email Address under Settings, then General, receives the recovery mode and critical error notices. Make sure you can read both.
  • Test the reset email now. In a private window, select "Lost your password?" and see that the message arrives.

When to get help

Ask your host if you have no way into the files or the database. Most of the fixes on this page are one command or one renamed folder for someone with that access.

If a check in "Rule out a break-in" came back positive, you have a different job from a lockout. Follow the runbook linked there.

If it is a plain lockout and you would rather not edit a database or a server by hand, hand it over. Being locked out of your own site is one issue on one site, which is what our one-time fix covers. It starts with a free diagnosis that gives you a written cause and a fixed quote.

Common questions

I do not remember my username. How do I find it?

You may not need it. The login form's first field is labeled "Username or Email Address", and the reset form takes either. If neither is accepted, list the accounts from the server with wp user list, or open the table whose name ends in users in your host's database tool and read the user_login column.

I reset the password and WordPress still refuses me. Why?

Read the message again, because it has probably changed. A request for a code is two-factor login. A line about too many attempts is a security plugin's lockout, which refuses the right password too. A page that reloads with no message is a cookie or address problem. If the message still says the password is incorrect, check that the command kept its single quotes and that you changed the account you are logging in with.

Can my hosting company let me back in?

Your host controls the server, so it can give you what the fixes on this page need: SSH, a file manager and a database tool. WordPress's documentation notes that tools such as phpMyAdmin are often made available by hosting providers. You can also send your host a command from this page and ask them to run it.

Another guide says to add a line to functions.php. Should I?

It is one of the methods WordPress documents, along with an emergency script you upload, and both are for when nothing else is open to you. The line in the theme's functions.php resets the password on every page load until you take it out. The script lets anyone who finds it change the password, so WordPress says to delete it when you are done. WP-CLI and the database tool leave nothing behind.

More on this subject

Quick Fix, done for you

Quick Fix is $49. One issue, one site, up to about an hour. No fix, no fee. 30-day warranty. It starts with a free diagnosis.