Troubleshooting

WordPress Login Redirect Loop — How to Fix It

You enter your password, and it just sends you back to login. Here's how to break the loop.

Quick Answer: A login redirect loop usually means a corrupted browser cookie, a mismatch between your site's Site Address and WordPress Address settings, a plugin conflict, or a corrupted .htaccess file. Start by clearing cookies or trying a private browser window. If that doesn't work, add define('WP_HOME','https://yoursite.com'); and define('WP_SITEURL','https://yoursite.com'); to wp-config.php to force-correct the URL settings.

Locked Out With a Redirect Loop Right Now?

Tell us what's happening and we'll help you get back in — or take it off your plate entirely going forward.

Why the Login Page Sends You Right Back to Itself

Every WordPress login attempt sets an authentication cookie, and every subsequent wp-admin page checks that cookie before showing the dashboard. A redirect loop means that check keeps failing silently — WordPress accepts the password, tries to send you to wp-admin, the cookie check fails, and it bounces you back to login, over and over. The fix is finding which part of that cookie-and-URL chain is broken.

Step 1: Clear Cookies and Try a Private Window

Before touching any files, clear your browser's cookies for the site, or simply try logging in from a private/incognito window. A stale, corrupted, or conflicting authentication cookie is one of the most common causes, and this rules it out — or fixes it — in under a minute.

Step 2: Check for a Site Address / WordPress Address Mismatch

If cookies aren't the issue, the next most common cause is a mismatch between the WordPress Address (URL) and Site Address (URL) values — for example, one set to http:// and the other to https://, or a leftover www. inconsistency after a domain change. Since this mismatch is exactly what's blocking wp-admin access, you can't fix it through the dashboard — instead, add these two lines to wp-config.php via FTP (with your actual site URL):

define( 'WP_HOME', 'https://yoursite.com' );
define( 'WP_SITEURL', 'https://yoursite.com' );

This overrides the database values directly, which resolves the loop immediately if a mismatch was the cause. Once you're able to log in again, go to Settings > General and correct both fields properly, then you can remove these lines from wp-config.php.

Step 3: Rule Out a Plugin Conflict

Security plugins and caching plugins are the most frequent culprits here, since both commonly interact with cookies and sessions. Rename the /wp-content/plugins folder via FTP to deactivate every plugin at once, then try logging in again. If it works, rename the folder back and reactivate plugins one at a time until the loop returns — that identifies the plugin responsible.

Step 4: Check for a Corrupted .htaccess File

Rename .htaccess to .htaccess-old via FTP and attempt to log in again. If that resolves the loop, the original file had a bad rewrite rule. After logging in, go to Settings > Permalinks and click Save Changes to regenerate a clean .htaccess automatically.

Related Troubleshooting Guides

Martin Van Den Boogerd
Martin Van Den Boogerd
Founder & Owner, CriticalWP — background in cybersecurity and municipal government infrastructure
More about Martin →

Common Questions

The most common causes are corrupted browser cookies, a mismatch between the Site Address (URL) and WordPress Address (URL) settings, a plugin conflict (especially security or caching plugins), or a corrupted .htaccess file. WordPress checks an authentication cookie on every admin page load, and if that check fails silently, it sends you back to login instead of showing an error.
Often, yes — clear your browser's cookies for the site (or try logging in from a private/incognito window) before anything else. A stale or corrupted authentication cookie is one of the most common causes and the fastest to rule out.
If wp-admin is inaccessible, add these two lines to wp-config.php with your actual URL: define('WP_HOME','https://yoursite.com'); define('WP_SITEURL','https://yoursite.com'); This overrides the database values directly and resolves a mismatch that's causing the loop.
Yes, especially security plugins, caching plugins, and any plugin that manipulates cookies or sessions. Rename the /wp-content/plugins folder via FTP to deactivate everything, then try logging in again. If it works, reactivate plugins one at a time to find the one responsible.
Yes, it can. Rename .htaccess to .htaccess-old via FTP and try logging in again. If that resolves it, go to Settings > Permalinks after logging in and click Save to regenerate a clean .htaccess file.

Locked out shouldn't mean losing hours.

Managed WordPress operations means someone with direct server and database access can resolve access issues fast — not a support ticket in a queue.