When WordPress admin login is not working, the public site may still look fine. The failure may be a login loop, a blank or critical-error Admin screen, a lost password email that never arrives, or a security plugin that blocked your IP after failed attempts.
Work this checklist in order. Once you can open Admin and complete a normal task, restore any settings, plugins, or theme changed only for testing and check login and other important site features again. If one covered WordPress issue is clearly to blame and you want help, use the $99 one-time fix after you can authorize access.
Define what failed
- Note whether
/wp-admin or /wp-login.php loads at all, redirects endlessly, shows a login form that rejects a known-good password, or lands on a blank page or critical error.
- Check the public homepage in a private window. If the whole site is offline, use the site down checklist first.
- If the screen says there has been a critical error, use the critical error checklist instead of guessing at passwords.
- If a maintenance message blocks Admin, clear any leftover
.maintenance file only after you confirm no update is still running, then return here. See also stuck in maintenance mode.
Rule out browser, cookies, and the wrong site
- Try a private window and a second browser with extensions disabled. A stale cookie or password manager autofill often looks like a broken login.
- Confirm you are on the intended domain and HTTPS. A leftover staging hostname or
www mismatch can send cookies to the wrong host and create a login loop.
- In Settings → General (once you regain access), check that WordPress Address and Site Address match your site’s intended setup. They can have different paths when WordPress is installed in its own directory. Do not change either URL just to make them match; ask your host if you suspect a wrong domain or HTTPS setting.
Reset access without guessing
- Use the lost-password link on the login form. If the email never arrives, check spam and ask your host whether outbound mail from WordPress is failing. Do not keep submitting wrong passwords while a lockout plugin is counting attempts.
- If you have host or database access, reset the admin password through the host’s WordPress tools or a documented database password reset. Prefer the host panel when it offers one.
- If a security or limit-login plugin may have blocked your IP, ask the host to confirm the block in that plugin’s settings or logs, then remove only the block that matches your current IP. Keep the plugin active when possible.
Read the error before disabling plugins
- Open the PHP error log in your hosting dashboard for the same minute Admin failed. Keep errors hidden from visitors. Do not share logs publicly; they may contain sensitive information.
- Look for a file path under
wp-content/plugins or wp-content/themes. That path is a lead, not proof of the whole cause.
- If Admin loads but one plugin’s screen fails, see also WordPress plugin not working.
Isolate conflicts safely
Use a staging copy when possible. Before changing the live site, take a backup and record which plugins are active. Disabling plugins can stop checkout, forms, bookings, and other features. Keep required security and login-related dependencies in mind when you test.
- If the log points to a security, captcha, or limit-login plugin, ask your host or the plugin vendor to check the matching error or block. On staging, test adjusting the relevant rule or temporarily disabling that plugin and retest basic WordPress login. A successful login with the plugin disabled does not show that its login or security features work; retest those after the plugin is restored or fixed.
- On staging, test disabling other regular plugins while keeping any plugin that provides the login feature you are testing and its required dependencies active. Retest login, then reactivate the other previously active plugins one at a time and check after each. If Admin will not load at all, use the critical error checklist to restore access before testing further. Must-use plugins and some caching components need separate checks.
- On staging, record the active theme and confirm a default WordPress theme is installed. Temporarily switch to that default theme and retest login, then restore the original theme and check again. If you cannot open Admin to switch themes, ask your host to test the change and confirm how to restore the original theme before changing files. A theme change can affect the public site’s layout and features.
If a plugin update started the lockouts, see also plugin update broke WordPress site.
Rule out cache and security layers
- Ask your host or cache provider to check whether private Admin or login responses are being served from public cache. Correct any unsuitable cache rule, then clear the affected cache.
- Check the security plugin or host firewall logs for a blocked login or Admin request. If a live test requires lowering protection, agree a short test window with your host and restore protection immediately afterward.
- After you regain access, check other important Admin features and restore any settings or plugins changed only for testing.
When a $99 one-time fix fits
Request the $99 one-time WordPress fix if you want help with one clearly defined issue on one WordPress site. Describe whether Admin loads, redirects, or errors, when it started, and the last change you made. We confirm the scope before work begins. Send credentials only through the private access link provided after your request is accepted.
Full rebuilds, new custom features, full migrations, and multiple unrelated issues are outside this offer.
Related checks
If the checks do not identify the cause, send your host the exact Admin URL behavior, the time it started, and any matching log lines. Suspected compromise needs a security investigation as well as restoring Admin access.