Skip to content

How to fix "Are you sure you want to do this?" in WordPress

WordPress shows this when a request arrives without a valid security token. Current versions word it "The link you followed has expired." The usual causes are a page left open too long, an upload larger than the server accepts, and a plugin that interferes with the tokens.

By
WP Ministry
Published
Tested on
WordPress 7.1.3, PHP 8.3.35

In short

  • It is a safety check, not damage. WordPress refused one request and changed nothing.
  • Current WordPress words the same check "The link you followed has expired."
  • If it happened once, go back, reload the page and try again.
  • If it happens when you upload a plugin or theme, the file is larger than the server accepts.

"Are you sure you want to do this?" is what older versions of WordPress said when a request reached the dashboard without a valid security token. Current versions run the same check and word it differently: a plain page that says "The link you followed has expired.", usually with a link that says "Please try again."

Every form and action link in the dashboard carries a token, which WordPress calls a nonce. It shows that the request came from a page WordPress built for you, in the session you are logged in to, and not from a link someone tricked you into opening. When the token is missing, out of date or made for another session, WordPress stops and shows this message.

Nothing has been changed or deleted. The one thing that did not happen is the action you asked for.

Find out which cause you have

  • It happened once, on a page that had been open for hours, or after you logged in again in another tab. The token ran out: use the first fix.
  • It happens when you upload a plugin, a theme or an import file. The file is too large: use the second fix.
  • It happens on many screens, whenever you save or follow an action link. A plugin or the theme is interfering: use the last fix.

Where it goes wrong

A page request passes through each of these in turn. This one comes from WordPress itself.

  1. Browser
  2. DNS
  3. HTTPS
  4. CDN or firewall
  5. Web server
  6. PHP
  7. WordPress (this error comes from here)
  8. Database and files

What causes it

  • The page was open too long, or you logged in again somewhere else

    Common

    Each form and action link carries a token that lasts between 12 and 24 hours and belongs to one login session. A tab left open overnight, or opened before you logged out and in again, holds tokens WordPress no longer accepts.

    Fix: Go back, reload the page and try again

  • The upload is larger than the server accepts

    Common

    When a form sends more data than PHP's post_max_size setting allows, PHP discards the whole form, token included. WordPress sees a request with no token.

    Fix: Raise PHP's upload limits in .htaccess, or Raise the limits through your host

  • A plugin or the theme interferes with the tokens

    Sometimes

    Code that changes how long tokens last, or how a form is put together, makes WordPress refuse requests on screens that have nothing to do with that plugin.

    Fix: Find the plugin that interferes

How to fix it

Go back, reload the page and try again

  • Easy
  • No risk
  • About 2 minutes
  1. Step 1: Go back to the page you came from

    Use the "Please try again." link, or your browser's Back button. If you had typed something into a form and can still see it, copy it somewhere safe before the next step.

  2. Step 2: Reload that page

    Reloading makes WordPress build the page again with fresh tokens. If it sends you to the login screen instead, log in.

  3. Step 3: Repeat the action

    Paste your text back if you need to, and save.

If the message returns on a page you have only just reloaded, the token's age is not the problem. Go on to the fixes below.

Raise PHP's upload limits in .htaccess

  • Takes care
  • Back up first
  • About 10 minutes
  • Steps tested on WordPress 7.1.3

PHP has two limits that matter here. upload_max_filesize is the largest single file it accepts. post_max_size is the largest form it accepts, files included. A file over the first limit but under the second gets a clear answer: "The uploaded file exceeds the upload_max_filesize directive in php.ini." A file over the second does not. PHP discards the whole form, and WordPress reports a missing token.

This fix applies to sites on Apache where PHP runs as part of the web server. Where PHP runs another way, the lines below are skipped and nothing changes: the next fix is the one to use.

  1. Step 1: Check the limit

    Go to Media, then Add Media File. Under the upload box WordPress shows "Maximum upload file size:" and a figure, which is the smaller of the two limits. If your file is larger than that, the limits are your cause.

  2. Step 2: Download a copy of .htaccess

    It is in the site's main folder, beside wp-config.php. Its name begins with a dot, so turn on "Show hidden files" in your file manager if you cannot see it.

  3. Step 3: Add these lines at the top of the file

    Put them above the line # BEGIN WordPress. Choose a figure larger than the file you need to upload, and never set post_max_size lower than upload_max_filesize.

    The first and last lines tell a server that runs PHP another way to skip the settings instead of failing on them.

    .htaccess
    <IfModule mod_php.c>
    php_value upload_max_filesize 64M
    php_value post_max_size 64M
    </IfModule>
  4. Step 4: Reload Media, then Add Media File

    If the figure has gone up, upload your file again.

If the figure has not changed, your server does not take PHP settings from .htaccess. Remove the lines and use the next fix. If the site shows a 500 error after you save, your host does not allow these settings in .htaccess: put your copy of the file back.

To undo it: Remove the four lines from .htaccess.

Raise the limits through your host

  • Easy
  • Low risk
  • About 15 minutes
  1. Step 1: Look for PHP settings in your hosting panel

    Many panels have a page where you can change PHP's settings for a site. Set upload_max_filesize and post_max_size to a figure larger than your file.

  2. Step 2: Or add a .user.ini file

    Where PHP runs as FastCGI, it reads settings from a file named .user.ini in the site's main folder. Create the file with these two lines. By default PHP looks at the file again every five minutes, so allow that long before you check the figure under Media, then Add Media File.

    .user.ini
    upload_max_filesize = 64M
    post_max_size = 64M
  3. Step 3: Or ask your host's support

    Tell them the size of the file, and ask them to raise both limits above it.

  4. Step 4: Or leave the upload form out of it

    Unzip the plugin or theme on your computer and upload its folder over SFTP, into wp-content/plugins/ or wp-content/themes/. It then appears in the dashboard, ready to activate. PHP's limits do not apply to files that arrive this way.

Find the plugin that interferes

  • Takes care
  • Low risk
  • About 20 minutes
  • Steps tested on WordPress 7.1.3

First, tell two cases apart. If the message appears on one plugin's own screen and nowhere else, that plugin sent a form WordPress could not accept. Update it. If that changes nothing, report it to its developer, because no setting of yours will fix it.

If the message appears across the dashboard, something is interfering with every token. The way to find it is to switch plugins off.

  1. Step 1: Switch every plugin off

    Go to Plugins, then Installed Plugins. Tick the box at the top of the list, choose Deactivate from the "Bulk actions" menu and press Apply. Plugins keep their settings while they are off.

  2. Step 2: If that shows the message too

    Switching plugins off is itself a request that needs a token. In your host's file manager or over SFTP, open wp-content/plugins/ and rename a plugin's folder, for example by adding -off to its name. WordPress can no longer find that plugin and stops running it. Begin with the one you installed or updated most recently.

  3. Step 3: Reload the page and repeat the action that failed

    If it works now, a plugin was the cause.

  4. Step 4: Switch the plugins back on one at a time

    Repeat the action after each one. The plugin that brings the message back is the one at fault. Leave it off, and look for an update or a replacement.

With WP-CLI, switch every plugin off:

bash
wp plugin deactivate --all

Then bring them back one at a time by folder name, repeating the action after each:

bash
wp plugin activate plugin-folder-name

If the message is still there with every plugin off, the theme is next. Switch to a default theme, as described for the white screen of death.

To undo it: Switch the plugins back on.

When to get help

If the message appears across the dashboard with every plugin off and a default theme active, something outside WordPress is changing requests before they arrive, such as a cache or a firewall on the server or in front of it. Finding it takes access to the server's configuration.

Common questions

Has my site been hacked?

No. The message is WordPress refusing a request it could not vouch for, which is the check doing its job. It exists so that a link on another website cannot make your browser delete a post or change a setting while you are logged in.

Why does WordPress ask "Do you really want to log out?"

It is the same check. A log-out link carries a token too. If you follow one without a valid token, such as a bookmarked link or one typed into a menu by hand, WordPress shows "You are attempting to log out of" with your site's name, and asks "Do you really want to log out?" Follow the link in that question and you are logged out.

Visitors see the message on a form on my site. Why?

A page cache can keep a copy of a page for longer than its tokens last. Every visitor then receives a form whose token has run out. Keep pages that hold forms out of the cache, or have the cache refresh them more often than every 12 hours.

Is this the same as a 403 Forbidden error?

Not quite. WordPress sends this page with the status 403, but the page is WordPress's own and the fixes are the ones above. A "Forbidden" page that comes from the web server is a different problem: see how to fix 403 Forbidden.

More on this subject

Would you rather we fixed it?

Quick Fix is $49. One issue, one site, up to about an hour. No fix, no fee. 30-day warranty. It starts with a free diagnosis.