"Can't login to wp-admin" is not a single token. WordPress may not accept the password, display the form again, get a 403 response, see a white screen, or even /wp-admin go to another domain. The right solution starts from the separation of these behaviors; Changing password for 403 error or clearing cache for fatal PHP does not help.
Quick answer: Record error text and status, try logging in in incognito window, check URL and HTTPS, then go to cookie, user account, security plugin, PHP or database based on the indication. Before directly changing the database or files, take a backup and never send the password or recovery link to an unknown person.
Which scenario do you see?
| Behavior | First check |
|---|---|
| "Wrong password" | Name Username, email and password recovery |
| No message return to the form | cookie, URL, HTTPS and cache |
| 403 or Access Denied | WAF, security plugin, permission and IP policy |
| Critical Error or white screen | PHP log, plugin and theme |
| Too many redirects | scheme, proxy, site URL and cookie domain |
| The user does not exist or has low access | User record and role/capability |
Low-risk browser tests
- Open the exact URL
/wp-login.phpdirectly. - Log in to the private window to reduce the effect of cookies and extensions.
- Clear cookies of the same domain, not all browser data.
- In DevTools, see Network, status and redirect destination.
- If you have multiple domains or www, make sure the form and destination are on the canonical domain.
Completely disabling browser security or accepting an invalid certificate is not the solution. The severe clock difference of the device can also disrupt the token or session of some layers, but it should be checked with evidence. Use and see the Spam folder. Failure to specify that the email was not sent or the account was not found will delay detection. If the site's email doesn't work but you have SSH access, WP-CLI can list users; The output contains private data and should not be made public:
If the username or password is not accepted
From "Lost your password?" Use and see the Spam folder. Failure to specify that the email was not sent or the account was not found will delay detection. If the site's email doesn't work but you have SSH access, WP-CLI can list users; The output contains personal data and should not be made public:
wp user list --fields=ID,user_login,user_email,roles
Changing the password with WP-CLI is possible, but the command containing the password can remain in history. Set a strong temporary password in a secure way and change it after login. Creating a new admin just to bypass the cause, without audit and subsequent removal, has residual access risk.
403, 401 or IP blocked
If the web server or WAF rejects the request before WordPress, changing the WordPress user is ineffective. Check Nginx/Apache log, CDN and security plugin with timestamp and IP. If the management IP restriction is intentional, it should be modified from a safe path and with a detailed whitelist; Do not turn off WAF for the entire site. Also check the ownership and permission of the file wp-login.php and location rules.
PHP error during login
The login form executes security plugin hooks, membership, captcha and SSO. If the public page is healthy but the login gives a 500 error, the PHP log of the same request is more valuable than testing images or page cache. Temporarily disable the plugin specified by trace and reproduce the result in staging. The guide Fix WordPress Critical Error explains how to securely log debug.log.
Roles and Capabilities
The login may be successful, but the user does not have access to the dashboard. In this case, check role, multisite, membership plugin and capability changes. Editing serialized data in the database with text search/replace is dangerous. Use the compatible WordPress API or WP-CLI and keep the current value before changing.
Multisite and Network Admin Address
In WordPress Multisite, being a member of a site is not the same as being a Super Admin. The user may be authenticated but not redirected to the dashboard of a site he is not a member of. Check the main network domain, domain mapping, cookie domain and route /wp-admin/network/ separately. Adding the capability manually to bypass the access model can break the boundaries of sites.
If there is a possibility of a security incident
Unwanted change of administrator email, creation of anonymous account, redirect to strange domain or new PHP files, the problem goes beyond "forgetting password". Before cleaning, save web server log, audit trail, user list and suspicious file sample. Passwords of the administrator, host, database and API keys must be rotated from a secure device, and previous sessions must be invalidated by changing salt or a valid tool.
Just deleting the anonymous account is not enough; The path of the attacker's entry, possible persistence, and the integrity of the core, plugin, and theme should be checked. restore should also be from the backup before the infection and then the input vulnerability is corrected.
Common mistakes
- Permanently turning off the security plugin or WAF.
- Creating several administrator accounts and forgetting to delete them.
- Sending password, cookie or reset link In the general message.
- Change
siteurlandhomewithout recognizing the proxy and canonical domain. - Editing the database directly without backup and paying attention to the table prefix.
After restoring access
View administrator accounts, active sessions, recent changes, and security logs. Change the temporary password, enable two-factor authentication if compatible, and document the root cause. If the problem is email reset, the SMTP and DNS delivery of the email should also be fixed separately.
When is expert help appropriate?
If the administrator account has changed, there are signs of security tampering, multiple layers of SSO/CDN are involved, or a database change is required, distributed testing can destroy evidence. WordPress Technical Problem Fix Provides the possibility of coordinated checking of user, cookie, PHP, WAF and database. For a specific redirect loop, follow the WordPress Login Redirect Loop guide.
FAQ
Is it safe to rename the security plugin folder?
As a short test with controlled access is possible, but it reduces protection. First, check the log and the possibility of whitelisting, and after the test, restore the status.
Why is the reset password email not sent?
It is possible that the email is from the wrong account, WordPress/PHP mail has failed to be sent, or there is a problem with SMTP delivery. Check the sending log and mailbox separately.
Is phpMyAdmin the only way to restore the administrator?
No. WP-CLI and Recovery Mode are often more controlled. Editing the database directly is the last option and requires backup.