Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not edit or delete wp-includes/pluggable.php as your first fix. In most WordPress incidents, that file is where execution finally stops, while the underlying fault is a plugin, theme, custom PHP, incompatible server environment, or damaged core files. Read the complete PHP message and stack trace, isolate the first non-core file named, and then repair that component. A corrupted core installation is possible, but it should be verified rather than assumed.

What pluggable.php does

/wp-includes/pluggable.php is a WordPress core file containing functions for authentication, users, cookies, nonces, passwords and email. Examples include wp_get_current_user(), wp_mail() and authentication-cookie functions; the complete file reference is documented in the WordPress Code Reference.

WordPress allows extensions to provide some replacement (“pluggable”) functions before core defines them. A badly written extension, duplicate include or modified core file can therefore produce an error that names this file. Core edits are overwritten by updates, can create version mismatches and may introduce security problems.

Read the complete error before changing anything

The last path in a fatal-error message is not necessarily the source. Start with the error type, the exact text, the line number and the first file outside wp-includes. Look especially for paths under /wp-content/plugins/, /wp-content/themes/, /wp-content/mu-plugins/ or a custom directory. Note whether the failure began after an update, theme change, PHP change, migration, restore or code edit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Error pattern What it commonly indicates First action
Cannot redeclare wp_mail() A plugin, theme or custom file declared the function twice. Use the earlier file in the trace to identify and deactivate the offending extension or duplicate include.
Cannot redeclare wp_get_current_user() A duplicate or incompatible pluggable implementation. Check plugins, must-use plugins, custom code and duplicate WordPress installations.
Call to undefined function ... in pluggable.php Missing or corrupt core, incorrect load order, an incompatible extension or an earlier failure. Read the full trace, verify core checksums and inspect the first non-core file.
Cannot modify header information Output was sent before WordPress could send headers. Open the “output started at” file and remove whitespace, a UTF-8 BOM or debugging output.
Allowed memory size exhausted The PHP memory limit was reached. Check PHP/server logs, workload and memory settings; do not assume more memory fixes a bug.
Parse error or syntax error Invalid PHP in a plugin, theme or custom file. Correct the file and line named before the core reference, or restore its last known-good copy.
There has been a critical error WordPress is hiding the underlying fatal error. Use Recovery Mode or temporary file logging.
Warning or deprecated notice only It may not be the outage’s cause. Find the first fatal error that follows and distinguish it from non-fatal notices.

WordPress lists plugin and theme conflicts, incompatible PHP, memory limits and damaged files among common fatal-error causes in its common-errors guide.

Preserve the site first

  • Make a full database and file backup, or clone the site to staging.
  • Do not overwrite the only copy of a modified theme or plugin.
  • Save the exact message, affected URL, time and recent changes.
  • For a business-critical or transactional site, preserve recent orders, comments and registrations before restoring anything.

WordPress recommends backing up before debugging changes; its debugging documentation explains the risks of exposing errors publicly.

Fastest recovery paths

Use Recovery Mode

WordPress 5.2 and later can send an email titled similar to “Your Site is Experiencing a Technical Issue.” Recovery Mode provides temporary administrator access while a fatal plugin, theme or custom-code component is paused. It is documented at wordpress.org/documentation/article/recovery-mode/.

  1. Open the recovery link and sign in.
  2. Record the plugin or theme identified.
  3. Deactivate or update it, roll back the recent change, or install a compatible version.
  4. Exit Recovery Mode, then test both the public site and /wp-admin/.

If no message arrives, check spam and the site administration address, ask the host whether outgoing mail works, and continue with file access or logs. Recovery Mode may not activate for every background or server-level failure and is not a permanent repair.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disable plugins through File Manager or FTP

  1. Open /wp-content/.
  2. Rename plugins to plugins.disabled to disable standard plugins, or rename only a suspected directory, such as plugin-folder to plugin-folder.disabled.
  3. If the site returns, restore the original plugins name when you disabled the whole directory.
  4. Reactivate extensions one at a time, testing the failing URL, login, editor, forms and checkout after each activation. Leave the offender disabled until it is updated, replaced, rolled back or repaired.

This technique does not automatically disable /wp-content/mu-plugins/, host-injected code, or drop-ins such as object-cache.php and advanced-cache.php. Also inspect custom files included from wp-config.php and child-theme code.

Switch to an installed default theme

Activate a supported default theme from the dashboard. If that is impossible, rename the active folder, for example /wp-content/themes/active-theme to active-theme.disabled, so WordPress can fall back to an available default. If the site works, inspect the child theme’s functions.php before the parent, remove accidental output or duplicate declarations, and restore a known-good copy. Install a default theme first if none is present.

Enable logging without exposing errors

Edit wp-config.php and place these settings before “That’s all, stop editing!”:

define( 'WP_DEBUG', true );
define( 'WP_DEBUG_LOG', true );
define( 'WP_DEBUG_DISPLAY', false );
@ini_set( 'display_errors', 0 );
  1. Reproduce the failure once.
  2. Read /wp-content/debug.log and the host’s PHP/server error log.
  3. Identify the first non-core path and line number.
  4. Remove or disable debugging after diagnosis.

Edit existing constants rather than defining them twice, use the boolean true (not 'true'), and keep logs inaccessible to visitors because they can reveal paths, usernames and other sensitive details. Afterward, set WP_DEBUG, WP_DEBUG_LOG and WP_DEBUG_DISPLAY to false.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix the specific underlying fault

Duplicate declarations

For “Cannot redeclare” errors, search for a plugin defining a core function without a guard, the same file included twice, a plugin copied into two directories, duplicate WordPress installations, malformed wp-config.php, a custom pluggable.php, or conflicting must-use and standard plugins. Remove or correct the extension that made the declaration; never rename the function in core.

A custom function may use a guard when that override is intentionally designed and loaded at the correct time:

if ( ! function_exists( 'example_function' ) ) {
    function example_function() {
        // Custom implementation.
    }
}

A guard is not an automatic fix for every WordPress override; compatibility with the current API still matters.

Header warnings

With “Cannot modify header information,” open the file named after “output started at.” Remove spaces or blank lines before <?php or after ?>, remove a UTF-8 BOM, and disable debugging or stray echo statements. The pluggable.php reference is often only where headers were needed later.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Code edited in functions.php

Restore the last known-good file through File Manager or FTP, then check for missing semicolons, unbalanced braces, output, a BOM, duplicate functions and calls to a plugin function that is no longer active.

Memory, PHP and server failures

Review the host-selected PHP version, required extensions, memory_limit, permissions, ownership, OPcache and persistent-cache behavior. Use a version supported by the current WordPress, theme, plugins and host; test a PHP change on staging rather than applying a universal upgrade or downgrade. For memory exhaustion, reduce the failing workload or fix the leak before increasing the limit. Contact the host for PHP-FPM, resource, permission, database or platform-change errors.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify or replace WordPress core safely

If extension and theme isolation do not explain the crash, verify the complete core. With WP-CLI, run from the installation directory (or supply --path):

wp core verify-checksums

A failed checksum or missing file warrants a clean WordPress package matching the installed version. Replace /wp-admin/, /wp-includes/ and matching root core files while preserving wp-config.php and wp-content/. Back up first, and do not overwrite custom root files whose purpose is unknown. Downloading one replacement pluggable.php can leave a mismatched core set.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WP-CLI alternatives

With SSH, correct permissions and a functioning WordPress installation, these commands can isolate extensions quickly:

wp plugin list
wp plugin deactivate --all
wp theme list
wp theme activate twentytwentyfive
wp option get template
wp option get stylesheet
wp core version

twentytwentyfive is only an example; activate a supported default theme that is actually installed. A host may need to run commands as the correct system user.

Cases that need extra care

Persistent errors after disabling a plugin

Check that the directory was renamed correctly, then inspect must-use plugins, drop-ins, generated files, database settings, theme code and opcode or page caches. Record the evidence before clearing caches.

Multisite

Network-activated plugins and network-level themes can affect every site. Test from Network Admin and back up the entire network database and file set before changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Possible compromise

Unexpected core changes, unfamiliar PHP files, unknown administrators or reinfection justify incident response. Preserve a backup, take the site offline if necessary, change hosting, database, WordPress, SSH/SFTP and API credentials, scan files and database, replace core from a clean package, remove unauthorized code and users, review access logs, and consider a professional malware-removal service. Not every pluggable.php error is a hack.

After the site returns

  • Update, roll back or replace the identified extension and document the change.
  • Reactivate remaining plugins individually and restore any renamed directories.
  • Disable production debugging and clear relevant caches after preserving logs.
  • Test login, password reset, email, forms, editor, REST API, cron, checkout and every critical admin page—not just the homepage.
  • Monitor logs for a recurrence before declaring the incident closed.

When paid help is worthwhile

Contact the host for server-level logs, limits, permissions, backups or staging. Contact the plugin or theme developer for a reproducible compatibility defect. Hire a WordPress developer or incident-response specialist when the site handles payments or regulated data, no reliable backup exists, fatal errors persist after isolation, or malware is suspected. Before authorizing work, confirm that the provider backs up first, uses staging where possible, identifies the originating extension instead of editing core, supplies a change log and can restore the site if a fix fails.

Troubleshooting checklist

  1. Back up files and database; record the complete message and recent changes.
  2. Try Recovery Mode and note the identified component.
  3. Enable file logging with display disabled; read debug.log and server logs.
  4. Isolate standard plugins, then must-use plugins, drop-ins, theme and custom includes.
  5. Match the error type to its source: duplicate declaration, headers, syntax, memory or undefined function.
  6. Verify core checksums; replace the matching core set only if evidence supports it.
  7. Check PHP compatibility, extensions, limits, permissions and caches.
  8. Restore safely, reactivate one component at a time, disable debugging and test critical workflows.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.