How to fix "Are you sure you want to do this?" in WordPress
WordPress shows this when a request arrives without a valid security token. Current versions word it "The link you followed has expired." The usual causes are a page left open too long, an upload larger than the server accepts, and a plugin that interferes with the tokens.
- By
- WP Ministry
- Published
- Tested on
- WordPress 7.1.3, PHP 8.3.35
In short
- It is a safety check, not damage. WordPress refused one request and changed nothing.
- Current WordPress words the same check "The link you followed has expired."
- If it happened once, go back, reload the page and try again.
- If it happens when you upload a plugin or theme, the file is larger than the server accepts.
"Are you sure you want to do this?" is what older versions of WordPress said when a request reached the dashboard without a valid security token. Current versions run the same check and word it differently: a plain page that says "The link you followed has expired.", usually with a link that says "Please try again."
Every form and action link in the dashboard carries a token, which WordPress calls a nonce. It shows that the request came from a page WordPress built for you, in the session you are logged in to, and not from a link someone tricked you into opening. When the token is missing, out of date or made for another session, WordPress stops and shows this message.
Nothing has been changed or deleted. The one thing that did not happen is the action you asked for.
Find out which cause you have
- It happened once, on a page that had been open for hours, or after you logged in again in another tab. The token ran out: use the first fix.
- It happens when you upload a plugin, a theme or an import file. The file is too large: use the second fix.
- It happens on many screens, whenever you save or follow an action link. A plugin or the theme is interfering: use the last fix.
Where it goes wrong
A page request passes through each of these in turn. This one comes from WordPress itself.
- Browser
- DNS
- HTTPS
- CDN or firewall
- Web server
- PHP
- WordPress (this error comes from here)
- Database and files
What causes it
The page was open too long, or you logged in again somewhere else
CommonEach form and action link carries a token that lasts between 12 and 24 hours and belongs to one login session. A tab left open overnight, or opened before you logged out and in again, holds tokens WordPress no longer accepts.
The upload is larger than the server accepts
CommonWhen a form sends more data than PHP's post_max_size setting allows, PHP discards the whole form, token included. WordPress sees a request with no token.
Fix: Raise PHP's upload limits in .htaccess, or Raise the limits through your host
A plugin or the theme interferes with the tokens
SometimesCode that changes how long tokens last, or how a form is put together, makes WordPress refuse requests on screens that have nothing to do with that plugin.
How to fix it
Go back, reload the page and try again
- Easy
- No risk
- About 2 minutes
Step 1: Go back to the page you came from
Use the "Please try again." link, or your browser's Back button. If you had typed something into a form and can still see it, copy it somewhere safe before the next step.
Step 2: Reload that page
Reloading makes WordPress build the page again with fresh tokens. If it sends you to the login screen instead, log in.
Step 3: Repeat the action
Paste your text back if you need to, and save.
If the message returns on a page you have only just reloaded, the token's age is not the problem. Go on to the fixes below.
Raise PHP's upload limits in .htaccess
- Takes care
- Back up first
- About 10 minutes
- Steps tested on WordPress 7.1.3
PHP has two limits that matter here. upload_max_filesize is the largest single file it accepts. post_max_size is the largest form it accepts, files included. A file over the first limit but under the second gets a clear answer: "The uploaded file exceeds the upload_max_filesize directive in php.ini." A file over the second does not. PHP discards the whole form, and WordPress reports a missing token.
This fix applies to sites on Apache where PHP runs as part of the web server. Where PHP runs another way, the lines below are skipped and nothing changes: the next fix is the one to use.
Step 1: Check the limit
Go to Media, then Add Media File. Under the upload box WordPress shows "Maximum upload file size:" and a figure, which is the smaller of the two limits. If your file is larger than that, the limits are your cause.
Step 2: Download a copy of .htaccess
It is in the site's main folder, beside
wp-config.php. Its name begins with a dot, so turn on "Show hidden files" in your file manager if you cannot see it.Step 3: Add these lines at the top of the file
Put them above the line
# BEGIN WordPress. Choose a figure larger than the file you need to upload, and never setpost_max_sizelower thanupload_max_filesize.The first and last lines tell a server that runs PHP another way to skip the settings instead of failing on them.
.htaccess<IfModule mod_php.c> php_value upload_max_filesize 64M php_value post_max_size 64M </IfModule>Step 4: Reload Media, then Add Media File
If the figure has gone up, upload your file again.
If the figure has not changed, your server does not take PHP settings from .htaccess. Remove the lines and use the next fix. If the site shows a 500 error after you save, your host does not allow these settings in .htaccess: put your copy of the file back.
To undo it: Remove the four lines from .htaccess.
Raise the limits through your host
- Easy
- Low risk
- About 15 minutes
Step 1: Look for PHP settings in your hosting panel
Many panels have a page where you can change PHP's settings for a site. Set
upload_max_filesizeandpost_max_sizeto a figure larger than your file.Step 2: Or add a .user.ini file
Where PHP runs as FastCGI, it reads settings from a file named
.user.iniin the site's main folder. Create the file with these two lines. By default PHP looks at the file again every five minutes, so allow that long before you check the figure under Media, then Add Media File..user.iniupload_max_filesize = 64M post_max_size = 64MStep 3: Or ask your host's support
Tell them the size of the file, and ask them to raise both limits above it.
Step 4: Or leave the upload form out of it
Unzip the plugin or theme on your computer and upload its folder over SFTP, into
wp-content/plugins/orwp-content/themes/. It then appears in the dashboard, ready to activate. PHP's limits do not apply to files that arrive this way.
Find the plugin that interferes
- Takes care
- Low risk
- About 20 minutes
- Steps tested on WordPress 7.1.3
First, tell two cases apart. If the message appears on one plugin's own screen and nowhere else, that plugin sent a form WordPress could not accept. Update it. If that changes nothing, report it to its developer, because no setting of yours will fix it.
If the message appears across the dashboard, something is interfering with every token. The way to find it is to switch plugins off.
Step 1: Switch every plugin off
Go to Plugins, then Installed Plugins. Tick the box at the top of the list, choose Deactivate from the "Bulk actions" menu and press Apply. Plugins keep their settings while they are off.
Step 2: If that shows the message too
Switching plugins off is itself a request that needs a token. In your host's file manager or over SFTP, open
wp-content/plugins/and rename a plugin's folder, for example by adding-offto its name. WordPress can no longer find that plugin and stops running it. Begin with the one you installed or updated most recently.Step 3: Reload the page and repeat the action that failed
If it works now, a plugin was the cause.
Step 4: Switch the plugins back on one at a time
Repeat the action after each one. The plugin that brings the message back is the one at fault. Leave it off, and look for an update or a replacement.
With WP-CLI, switch every plugin off:
wp plugin deactivate --allThen bring them back one at a time by folder name, repeating the action after each:
wp plugin activate plugin-folder-nameIf the message is still there with every plugin off, the theme is next. Switch to a default theme, as described for the white screen of death.
To undo it: Switch the plugins back on.
When to get help
If the message appears across the dashboard with every plugin off and a default theme active, something outside WordPress is changing requests before they arrive, such as a cache or a firewall on the server or in front of it. Finding it takes access to the server's configuration.
Common questions
Has my site been hacked?
No. The message is WordPress refusing a request it could not vouch for, which is the check doing its job. It exists so that a link on another website cannot make your browser delete a post or change a setting while you are logged in.
Why does WordPress ask "Do you really want to log out?"
It is the same check. A log-out link carries a token too. If you follow one without a valid token, such as a bookmarked link or one typed into a menu by hand, WordPress shows "You are attempting to log out of" with your site's name, and asks "Do you really want to log out?" Follow the link in that question and you are logged out.
Visitors see the message on a form on my site. Why?
A page cache can keep a copy of a page for longer than its tokens last. Every visitor then receives a form whose token has run out. Keep pages that hold forms out of the cache, or have the cache refresh them more often than every 12 hours.
Is this the same as a 403 Forbidden error?
Not quite. WordPress sends this page with the status 403, but the page is WordPress's own and the fixes are the ones above. A "Forbidden" page that comes from the web server is a different problem: see how to fix 403 Forbidden.
- GuideLocked out of WordPress admin: find which lockout you have and get back in
- GuideSlow WordPress admin: how to find the cause and fix it
- ResourceWooCommerce checkout is down: a runbook
- GuideWordPress site not showing up on Google: what to check, in order
- Guideadmin-ajax.php high CPU usage in WordPress: how to find what is calling it
- GuideHow to change WordPress permalinks without breaking your old links

