Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If WordPress accepts your password but sends you back to the login screen, the password may be fine: the browser may not be saving or returning the authentication cookie WordPress needs. Start with the site’s cookies and canonical login URL, then check URL settings, plugins, caching, and HTTPS or proxy redirects—in that order. Don’t change database or server settings until you have a backup.

Start with the login URL and the exact redirect

Open your site’s public address followed by /wp-login.php, for example https://example.com/wp-login.php. Replace the example with the site’s actual scheme and hostname. WordPress documents wp-login.php as the login page in the site root; a WordPress installation in a subdirectory has a different path. See WordPress’s login documentation and O’Reilly’s WordPress reference.

Going to /wp-admin/ while logged out normally sends you to the login page, so that redirect alone is expected. If the browser keeps looping, note the addresses it visits and whether they switch between http and https, or between www and non-www. Browser developer tools’ Network panel can show the redirect chain; a header-inspection tool can also help.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clear the site’s cookies and cache

Delete cookies and cached data for the affected domain, close the tab, then try again in a private window. Make sure cookies are enabled. WordPress’s login troubleshooting guide recommends clearing cookies and cache, and its developer documentation explains that a login loop can happen when WordPress cannot set or read its test or authentication cookies.

A successful password check does not guarantee that the login session has been established: the next request still needs to carry a valid cookie. If private browsing works, focus on the regular browser’s saved cookies and session state before changing the site.

Make sure the WordPress URLs agree

Compare the public URL in the browser with the WordPress URL settings. The scheme (http or https), hostname, and installation path need to match across the settings that control the site.

  • Check WP_HOME and WP_SITEURL in wp-config.php, if they are defined.
  • Check the home and siteurl values in the WordPress options table.
  • Check whether the host separately redirects HTTP to HTTPS or redirects between www and non-www.

Conflicting constants, database values, or mixed HTTP/HTTPS settings are documented causes of redirect loops. This is especially worth checking after a migration, clone, domain change, or SSL change: an old staging hostname or HTTP URL may remain in one location. Back up the site before editing wp-config.php or database options. WordPress’s login documentation describes these URL checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test for a plugin or theme conflict

If you cannot reach the dashboard, temporarily rename wp-content/plugins using your host’s file manager or another file-access method—for example, to plugins.disabled—then retry the login. WordPress documents this as a way to rule out plugin conflicts. If the loop stops, restore the directory name and reactivate plugins one at a time until the problem returns. That narrows down the component to investigate.

If disabling plugins does not change the result, test with a default WordPress theme and inspect any theme code that handles login or redirects. Pay particular attention to security, membership, redirection, caching, and SSL plugins, since they can affect login redirects, cookies, or HTTPS behavior. Avoid leaving plugins disabled longer than needed to diagnose the issue.

Check HTTPS, CDN, and reverse-proxy redirects

If the redirect alternates between HTTP and HTTPS, the site may be caught between layers that disagree about whether the original request was secure. WordPress warns that forcing SSL behind a reverse proxy can cause an infinite redirect loop if the origin does not receive or correctly handle the forwarded HTTPS state. See WordPress’s HTTPS guidance.

  • Confirm that the CDN or load balancer terminates TLS as expected.
  • Check that the origin receives the correct HTTP_X_FORWARDED_PROTO value, or the equivalent signal used by the hosting platform.
  • Make sure FORCE_SSL_ADMIN is consistent with the proxy setup.
  • Determine which layer is responsible for the canonical HTTP-to-HTTPS redirect; avoid competing redirects at the proxy, server, and WordPress levels.

If the browser keeps switching schemes, correct the proxy or origin’s HTTPS detection rather than repeatedly changing WordPress URLs. The exact configuration depends on the host, CDN, proxy, and web server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep login and authenticated pages out of caches

A cached login response or redirect can make a valid login appear to fail. Exclude wp-login.php and cookie-based authenticated sessions from page caching, as WordPress’s login documentation advises. After changing cache rules, purge the relevant page, object, CDN, and browser caches so an old response is not reused.

Use the symptom to choose the next check

What you observe Likely area to check Next step
Login works in a private window Browser cookies or session state Clear the affected domain’s cookies and inspect cookie domain, path, and secure attributes.
Redirects alternate between HTTP and HTTPS SSL, proxy, or duplicate redirect rules Check forwarded HTTPS signaling and which layer owns the redirect. WordPress HTTPS guidance.
The URL changes to an old domain or staging host WordPress URL configuration Compare WP_HOME, WP_SITEURL, home, and siteurl. WordPress login documentation.
The loop stops when plugins are disabled Plugin or theme conflict Restore plugins and reactivate them one at a time to identify the conflict.
Only some users or networks fail Firewall, CDN, cache, or host controls Review WAF events, rate limits, bot rules, cache behavior, and proxy logs. WordPress’s login troubleshooting guide also notes that firewalls can block login attempts.

When to involve your host

Contact your hosting provider or site administrator if the redirect chain points to server rules, proxy headers, PHP session behavior, or controls you cannot access. Check firewall or web-application-firewall events when the browser receives a 403 or 429, or when the problem occurs only from particular networks. Share the redirect chain and the time of a failed attempt; those details can help distinguish a WordPress setting from a host or edge-layer rule.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.