DEV Community

Amanur Rahman
Amanur Rahman

Posted on Originally published at amanurrahman.com

Debugging the WordPress Login Redirect Loop: A Locked-Out Checklist

A WordPress login redirect loop looks scary: you enter valid credentials and land back on the login form. In practice it is almost always an access problem, not data loss, and the causes follow a predictable order.

What is actually happening

After login, WordPress sets an auth cookie and sends you to the dashboard. The dashboard checks for that cookie. If it is missing, blocked, or set for a different host, WordPress treats you as logged out and redirects you back. So almost every cause is one of three things: an address mismatch, a redirect conflict, or something blocking the cookie.

Quick checks first

  • Clear cookies for the site and try a private window
  • Try a second browser (rules out extensions)
  • Make sure you are on the canonical host (https, www or non-www)

1. Mismatched siteurl and home

The most common cause, usually after an SSL, www, or domain change. If you can't open Settings, General, force the values in wp-config.php:

define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );
Enter fullscreen mode Exit fullscreen mode

Remove them once the real settings are correct, since they override the dashboard. If that doesn't help, update the siteurl and home rows in the options table (check your table prefix).

2. HTTPS conflicts

Cloudflare's Flexible SSL talks HTTPS to the visitor but HTTP to your origin. If the origin also forces HTTPS, the two bounce each other until the browser reports too many redirects. Switch to Full (strict) with a valid origin certificate. Behind a proxy, WordPress may need to trust the forwarded header:

if ( isset( $_SERVER['HTTP_X_FORWARDED_PROTO'] ) && $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https' ) {
    $_SERVER['HTTPS'] = 'on';
}
Enter fullscreen mode Exit fullscreen mode

Only use this if your host or proxy actually sets that header. Also make sure only one thing forces HTTPS: host setting, plugin, or .htaccess rule.

3. .htaccess

Rename .htaccess to .htaccess-old and test. If login works, regenerate it from Settings, Permalinks, then re-add custom rules one at a time.

4. Cookies and domains

A stray COOKIE_DOMAIN constant, www and non-www mixed up, or whitespace before the opening PHP tag in wp-config.php or functions.php (output sent before headers) can all stop the cookie being set.

5. Plugins and theme

Rename wp-content/plugins to deactivate everything at once without dashboard access, then reactivate one by one. Rename the active theme folder to fall back to a default theme.

6. Cache and security plugins

Exclude wp-login.php and wp-admin from page caching, and check that a login-URL, 2FA, or firewall plugin hasn't blocked your own IP.

Quick FAQ

Will fixing it delete my content?
No. The loop affects access, not posts or media. Back up first anyway.

What does "too many redirects" mean?
The browser was sent in a circle between addresses. Same family of problem.

When should I hire help?
No file access, Cloudflare or server-level SSL questions, redirects to other sites, or unknown admin users.

Can a plugin cause it?
Yes, security, caching, redirect, and login-page plugins most often.

I wrote the full version, with a 12-step checklist and a fix-it-yourself-or-hire-help table, on my site: Locked Out of WordPress? Fix the Login Loop.

Top comments (0)