The WordPress message “Cookies are blocked due to unexpected output” usually means that PHP sent text, a warning, whitespace, or another response before WordPress could set its login test cookie. Start by finding the first warning and its file-and-line reference, then isolate recently changed PHP, plugins, and themes. Clear cookies and cache when the problem follows a migration, but do not treat browser settings as the explanation for a visible “headers already sent” warning.
What the error actually means
WordPress uses a temporary wordpress_test_cookie to verify that the browser accepts cookies during login. If PHP produces output before WordPress sends its HTTP headers, the test cookie may not be set and the login form reports that cookies are blocked. The wording therefore describes a failed cookie test, not proof that the browser is refusing cookies.
Typical premature output includes a PHP warning displayed above the login form, text accidentally printed by a plugin or theme, whitespace before the opening <?php tag, trailing output after a PHP file, or a UTF-8 byte-order mark (BOM). A historical support case was fixed by removing two blank lines at the end of functions.php; that is a useful clue, not a universal rule.
Use the warning and logs to locate the source
- Read the complete login error. If a PHP notice or warning appears above it, record the first filename and line shown, especially any phrase such as “output started at.”
- Inspect the PHP and server error logs for the same request. The earliest output reference is generally more useful than the final cookie message.
- Check the file named in the warning before changing browser settings. Preserve a backup or download a copy before editing production files.
Review wp-config.php, the active theme’s functions.php, and plugin or theme files edited immediately before the failure. Look for a BOM, blank characters before <?php, closing-tag output, debugging statements, accidental HTML, or a warning generated by a recent code change.
Recommended Free Tools
#1 Best Overall
- easy to use
- Free app
- Compatible with all devices
- It gives the best comparison between ten different hosts
Isolate plugins when wp-admin is unavailable
You can disable code without dashboard access if you have hosting file-manager, SFTP, or FTP access.
- Open the site’s
wp-content/pluginsdirectory. - Rename the directory of the suspected plugin, for example from
plugin-nametoplugin-name.disabled. If no suspect stands out, temporarily renamepluginsto another name; this disables all standard plugins. - Try the login again in a private browser window.
- If login works, restore the original directory name. Reactivate plugins one at a time, testing after each activation, until the conflict returns.
Make each rename reversible and record what you changed. If the error remains with every plugin disabled, plugin code is less likely to be the immediate source; continue with theme and file checks.
Rank #2
Test the active theme
- In
wp-content/themes, identify the active theme directory from your hosting files. - Rename that directory temporarily, such as adding
.disabledto its name. - WordPress should fall back to another installed theme. Attempt the login.
- Restore the original directory name after testing.
If the error disappears only with the fallback theme, inspect the original theme’s functions.php and recent changes, then contact its maintainer with the exact warning and line number.
When browser cookies and cache are relevant
Cookies must be enabled for WordPress authentication. After a domain, host, or URL migration, clear cookies for the affected site and retry in a private window. Also clear the site’s server-side or page-cache plugin cache when the migration left stale responses.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsThese steps address a genuine browser or migration state problem; they do not repair PHP output. If the login page still shows a warning or “headers already sent” location, return to the file and log investigation.
Check custom login routes and caching
Plugins that replace or extend the standard login URL can be affected when a host or reverse proxy caches a login response. If the site uses Theme My Login or a similar custom-login plugin, ask the host whether the plugin’s current login-related paths are excluded from caching. Exclusion rules are plugin-specific and should be taken from the active plugin’s current documentation rather than copied from an unrelated setup.
Rank #4
Choose the next branch from the evidence
| What you observe | Most useful next action |
|---|---|
| A PHP warning names a file and line | Inspect that file for unintended output, BOM, whitespace, or the warning’s underlying code. |
| Error vanishes when a plugin is disabled | Restore plugins and reactivate individually to identify the conflicting plugin. |
| Error vanishes with a fallback theme | Inspect or update the original theme and provide its maintainer the log details. |
| Problem began after a migration, with no PHP warning | Clear site cookies and relevant server/cache-plugin caches; verify the site’s configured URL and login domain. |
| Only a custom login URL fails | Have the host check cache exclusions for that plugin’s routes. |
| No branch identifies a cause | Escalate with the complete error, logs, named file and line, recent changes, and isolation results. |
What to send your host or developer
- The complete message, including every PHP warning and any “output started at” reference.
- The PHP/server log entries for the failed request.
- The time the issue began and any plugin, theme, PHP, code, host, or migration change immediately beforehand.
- Whether renaming plugins or the active theme changed the result.
- Whether the failure affects the standard login, a custom login route, or both.
Ask the host to check PHP logs, response headers, and applicable cache rules. Fix the plugin, theme, encoding, or configuration that produced the output instead of hiding notices or downgrading WordPress based on an old, version-specific discussion.
Quick Recap
Best Value
- Free WordPress Hosting Guide Android Application. It Contains: A Brief Overview of WordPress Hosting, 9 Major Benefits of Managed WordPress Hosting.
- 5 Simple Steps to Choose WordPress Hosting, How to Maximize Your WordPress Hosting and Blogging Success, How to Choose the Best WordPress Hosting Provider, Optimize Your Blog with VIP Word.
- Press Hosting, What You Should Know to Choose the Best WordPress Hosting and Much More.
Prevent a recurrence
- Keep a restorable backup before editing PHP or renaming production directories.
- Test plugin and theme updates on a staging copy when possible.
- Save PHP files as UTF-8 without a BOM and keep output outside PHP logic intentional.
- Remove temporary debugging output after troubleshooting.
- Document cache exclusions for any custom login route and retest login after migrations.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




