How to fix a WordPress login page that keeps refreshing or redirecting
When the WordPress login page reloads or sends you back to itself with no error, the login is being lost on the way. Either the browser is not keeping WordPress's cookie, or the form is redirected before WordPress reads it. A private window tells you which side to look at.
- By
- WP Ministry
- Published
- Tested on
- WordPress 7.1.3, PHP 8.3.35
In short
- Your account and your content are fine. The login is being lost between the browser and WordPress.
- Try a private window first. If you get in there, clear the site's cookies in your usual browser.
- Check that the two site addresses in WordPress's settings match the address you type, including https and www.
- If the addresses are right, switch the plugins off, then look at .htaccess.
You type the right username and password, press Log In, and the login form comes back empty. There is no error to read, which is what makes this one hard. A wrong password gets a message that says so. A silent reload means the login never arrived, or it worked and the browser did not keep the cookie that proves it.
Your account, your password and your content are not affected. Each fix below removes one thing that can stand between the form and WordPress.
Where it goes wrong
A page request passes through each of these in turn. This one comes from WordPress itself.
- Browser
- DNS
- HTTPS
- CDN or firewall
- Web server
- PHP
- WordPress (this error comes from here)
- Database and files
What causes it
The browser is not keeping the login cookie
CommonWordPress keeps you logged in with a cookie. An old cookie from the same site, a browser set to block cookies or a privacy extension can stop the new one from being kept.
The site's address settings do not match the address you use
CommonThe login form is sent to the WordPress Address in the site's settings. If that is not the address you are on, such as http for https, with or without www, or an old domain, the server forwards the request and what you typed is lost on the way.
A plugin is sending you back
SometimesA caching plugin that stores the login page, or a login, security or membership plugin that redirects people after they log in, can return you to the form.
A redirect in .htaccess catches the login
SometimesA redirect rule written for another address, or left behind by a plugin, forwards the login form's request. It arrives as a fresh visit to the login page.
wp-config.php names the wrong cookie domain
RareA COOKIE_DOMAIN line that names a domain other than the site's makes every browser refuse the cookies WordPress sends.
How to fix it
Make the site addresses match the address you use
- Takes care
- Back up first
- About 15 minutes
- Steps tested on WordPress 7.1.3
WordPress stores two addresses: the WordPress Address and the Site Address. Unless WordPress was deliberately installed in a subfolder of its own, both are the address you type in the browser, with the same http or https and the same www or none.
Step 1: See what WordPress has
Since you cannot reach the dashboard, look in the database. In your host's database tool, open the
wp_optionstable and read the rows namedsiteurlandhome. The table's prefix may differ fromwp_.Step 2: Set both in wp-config.php
Add these two lines above the line that says "That's all, stop editing!". Replace
https://example.comwith your site's address, with no slash at the end.wp-config.phpdefine( 'WP_HOME', 'https://example.com' ); define( 'WP_SITEURL', 'https://example.com' );Step 3: Log in
The two lines overrule the database. While they are there, the two fields under Settings, then General cannot be edited.
With WP-CLI, read the two addresses:
wp option get home
wp option get siteurlAnd set them:
wp option update home 'https://example.com'
wp option update siteurl 'https://example.com'To undo it: Remove the two lines from wp-config.php, or set the old values again.
Switch every plugin off, then find the one
- Takes care
- Low risk
- About 20 minutes
- Steps tested on WordPress 7.1.3
Step 1: Rename the plugins folder
In your host's file manager or over SFTP, rename
wp-content/pluginstoplugins-off. No plugin can load.Step 2: Log in and open the Plugins screen
If you get in, a plugin was the cause. Opening the Plugins screen makes WordPress record every plugin it cannot find as switched off.
Step 3: Rename the folder back
The plugins are listed again, all inactive. Nothing is lost.
Step 4: Activate them one at a time
Log out and in again after each one. The plugin that brings the loop back is the cause. Start with caching plugins, and with any plugin that changes the login page or protects it. A caching plugin must never store
wp-login.phpor anything under/wp-admin/.
With WP-CLI:
wp plugin deactivate --allTo undo it: Activate the plugins again from the Plugins screen.
Replace .htaccess with WordPress's standard one
- Easy
- Back up first
- About 5 minutes
- Steps tested on WordPress 7.1.3
This applies to sites on Apache or LiteSpeed. A sign of this cause: the address bar changes to an address you did not type.
Step 1: Download a copy of .htaccess
It sits in the site's main folder, beside
wp-config.php. Turn on "Show hidden files" if you cannot see it.Step 2: Replace everything in it with this
This is what WordPress itself writes for a site at the root of its domain.
.htaccess# BEGIN WordPress <IfModule mod_rewrite.c> RewriteEngine On RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> # END WordPressStep 3: Log in
If you get in, a rule in the old file was forwarding the login. Put your other rules back one section at a time from the copy. Look hardest at lines that begin with
RewriteRuleorRedirectand name a full address.
If WordPress is installed in a subfolder, such as example.com/blog, do not paste the block above. Rename .htaccess to .htaccess-old, log in, then go to Settings, then Permalinks and press Save Changes. WordPress writes a fresh file with the right paths.
To undo it: Put your copy of the old .htaccess back.
When to get help
If a private window does not help, both addresses are right, every plugin is off and .htaccess is the standard one, the cause is outside WordPress. It can be a proxy, CDN or cache in front of the site that redirects or stores the login page. That needs someone who can see how the site is served.
Common questions
It only happens on one computer. Why?
Then the site is fine and that browser is not keeping the cookie. The first fix covers it: a private window, then the site's cookies, then extensions.
It began right after I switched the site to https. What changed?
The addresses in WordPress's settings probably still begin with http. Set both to https with the second fix. If the browser then reports too many redirects, the https is being added by a service in front of your server and WordPress has to be told about it: the third fix on the mixed content page does that. If it shows a certificate warning instead, see "Your connection is not private".
Could my password be wrong?
No. A wrong password or username gets an error message on the login page. No message means the login was lost before or after WordPress checked it.
The login page says "Forbidden" instead. Is that the same thing?
No. That is the server refusing you, not losing your login. See 403 Forbidden.
- GuideLocked out of WordPress admin: find which lockout you have and get back in
- GuideSlow WordPress admin: how to find the cause and fix it
- ResourceWooCommerce checkout is down: a runbook
- GuideWordPress site not showing up on Google: what to check, in order
- Guideadmin-ajax.php high CPU usage in WordPress: how to find what is calling it
- GuideHow to change WordPress permalinks without breaking your old links

