Skip to content

How to fix a WordPress login page that keeps refreshing or redirecting

When the WordPress login page reloads or sends you back to itself with no error, the login is being lost on the way. Either the browser is not keeping WordPress's cookie, or the form is redirected before WordPress reads it. A private window tells you which side to look at.

By
WP Ministry
Published
Tested on
WordPress 7.1.3, PHP 8.3.35

In short

  • Your account and your content are fine. The login is being lost between the browser and WordPress.
  • Try a private window first. If you get in there, clear the site's cookies in your usual browser.
  • Check that the two site addresses in WordPress's settings match the address you type, including https and www.
  • If the addresses are right, switch the plugins off, then look at .htaccess.

You type the right username and password, press Log In, and the login form comes back empty. There is no error to read, which is what makes this one hard. A wrong password gets a message that says so. A silent reload means the login never arrived, or it worked and the browser did not keep the cookie that proves it.

Your account, your password and your content are not affected. Each fix below removes one thing that can stand between the form and WordPress.

Where it goes wrong

A page request passes through each of these in turn. This one comes from WordPress itself.

  1. Browser
  2. DNS
  3. HTTPS
  4. CDN or firewall
  5. Web server
  6. PHP
  7. WordPress (this error comes from here)
  8. Database and files

What causes it

  • The browser is not keeping the login cookie

    Common

    WordPress keeps you logged in with a cookie. An old cookie from the same site, a browser set to block cookies or a privacy extension can stop the new one from being kept.

    Fix: Try a private window, then clear the site's cookies

  • The site's address settings do not match the address you use

    Common

    The login form is sent to the WordPress Address in the site's settings. If that is not the address you are on, such as http for https, with or without www, or an old domain, the server forwards the request and what you typed is lost on the way.

    Fix: Make the site addresses match the address you use

  • A plugin is sending you back

    Sometimes

    A caching plugin that stores the login page, or a login, security or membership plugin that redirects people after they log in, can return you to the form.

    Fix: Switch every plugin off, then find the one

  • A redirect in .htaccess catches the login

    Sometimes

    A redirect rule written for another address, or left behind by a plugin, forwards the login form's request. It arrives as a fresh visit to the login page.

    Fix: Replace .htaccess with WordPress's standard one

  • wp-config.php names the wrong cookie domain

    Rare

    A COOKIE_DOMAIN line that names a domain other than the site's makes every browser refuse the cookies WordPress sends.

    Fix: Remove a wrong COOKIE_DOMAIN from wp-config.php

How to fix it

Try a private window, then clear the site's cookies

  • Easy
  • No risk
  • About 5 minutes
  1. Step 1: Log in from a private window

    Open a private or incognito window and go to your login page. A private window starts with no cookies and, in most browsers, no extensions.

  2. Step 2: If that works, clear the site's cookies

    In your usual browser, delete the cookies stored for your site's address, then log in again. If it still fails there, switch off privacy and ad-blocking extensions for the site, and check that the browser is not set to block all cookies.

  3. Step 3: If the private window fails too

    The browser is not the cause. Go to the next fix.

Make the site addresses match the address you use

  • Takes care
  • Back up first
  • About 15 minutes
  • Steps tested on WordPress 7.1.3

WordPress stores two addresses: the WordPress Address and the Site Address. Unless WordPress was deliberately installed in a subfolder of its own, both are the address you type in the browser, with the same http or https and the same www or none.

  1. Step 1: See what WordPress has

    Since you cannot reach the dashboard, look in the database. In your host's database tool, open the wp_options table and read the rows named siteurl and home. The table's prefix may differ from wp_.

  2. Step 2: Set both in wp-config.php

    Add these two lines above the line that says "That's all, stop editing!". Replace https://example.com with your site's address, with no slash at the end.

    wp-config.php
    define( 'WP_HOME', 'https://example.com' );
    define( 'WP_SITEURL', 'https://example.com' );
  3. Step 3: Log in

    The two lines overrule the database. While they are there, the two fields under Settings, then General cannot be edited.

With WP-CLI, read the two addresses:

bash
wp option get home
wp option get siteurl

And set them:

bash
wp option update home 'https://example.com'
wp option update siteurl 'https://example.com'

To undo it: Remove the two lines from wp-config.php, or set the old values again.

Switch every plugin off, then find the one

  • Takes care
  • Low risk
  • About 20 minutes
  • Steps tested on WordPress 7.1.3
  1. Step 1: Rename the plugins folder

    In your host's file manager or over SFTP, rename wp-content/plugins to plugins-off. No plugin can load.

  2. Step 2: Log in and open the Plugins screen

    If you get in, a plugin was the cause. Opening the Plugins screen makes WordPress record every plugin it cannot find as switched off.

  3. Step 3: Rename the folder back

    The plugins are listed again, all inactive. Nothing is lost.

  4. Step 4: Activate them one at a time

    Log out and in again after each one. The plugin that brings the loop back is the cause. Start with caching plugins, and with any plugin that changes the login page or protects it. A caching plugin must never store wp-login.php or anything under /wp-admin/.

With WP-CLI:

bash
wp plugin deactivate --all

To undo it: Activate the plugins again from the Plugins screen.

Replace .htaccess with WordPress's standard one

  • Easy
  • Back up first
  • About 5 minutes
  • Steps tested on WordPress 7.1.3

This applies to sites on Apache or LiteSpeed. A sign of this cause: the address bar changes to an address you did not type.

  1. Step 1: Download a copy of .htaccess

    It sits in the site's main folder, beside wp-config.php. Turn on "Show hidden files" if you cannot see it.

  2. Step 2: Replace everything in it with this

    This is what WordPress itself writes for a site at the root of its domain.

    .htaccess
    # BEGIN WordPress
    <IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
    RewriteBase /
    RewriteRule ^index\.php$ - [L]
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule . /index.php [L]
    </IfModule>
    # END WordPress
  3. Step 3: Log in

    If you get in, a rule in the old file was forwarding the login. Put your other rules back one section at a time from the copy. Look hardest at lines that begin with RewriteRule or Redirect and name a full address.

If WordPress is installed in a subfolder, such as example.com/blog, do not paste the block above. Rename .htaccess to .htaccess-old, log in, then go to Settings, then Permalinks and press Save Changes. WordPress writes a fresh file with the right paths.

To undo it: Put your copy of the old .htaccess back.

When to get help

If a private window does not help, both addresses are right, every plugin is off and .htaccess is the standard one, the cause is outside WordPress. It can be a proxy, CDN or cache in front of the site that redirects or stores the login page. That needs someone who can see how the site is served.

Common questions

It only happens on one computer. Why?

Then the site is fine and that browser is not keeping the cookie. The first fix covers it: a private window, then the site's cookies, then extensions.

It began right after I switched the site to https. What changed?

The addresses in WordPress's settings probably still begin with http. Set both to https with the second fix. If the browser then reports too many redirects, the https is being added by a service in front of your server and WordPress has to be told about it: the third fix on the mixed content page does that. If it shows a certificate warning instead, see "Your connection is not private".

Could my password be wrong?

No. A wrong password or username gets an error message on the login page. No message means the login was lost before or after WordPress checked it.

The login page says "Forbidden" instead. Is that the same thing?

No. That is the server refusing you, not losing your login. See 403 Forbidden.

More on this subject

Would you rather we fixed it?

Quick Fix is $49. One issue, one site, up to about an hour. No fix, no fee. 30-day warranty. It starts with a free diagnosis.