When WordPress shows “Are you sure you want to do this?” (sometimes with “Please try again”), the page usually failed a security check on an Admin action. WordPress uses short-lived tokens (nonces) so a form or link matches the signed-in session. An expired tab, a cached Admin page with an old token, a cookie problem, or a security plugin interfering with the request can all trigger this screen. The message itself rarely names the cause.
Work this checklist in order. Prefer staging when you can reproduce the action there. Take a backup before changing cache rules or security plugins on production. This article is about nonce / request-verification failures on Admin actions. If you cannot sign in at all, start with the admin login checklist. If one covered WordPress issue is clearly to blame and you want help, use the $99 one-time fix. We confirm the scope before work begins.
Define what failed
- Confirm the screen appears after an Admin action (save, delete, bulk edit, plugin/theme action, settings submit), not on a random public page.
- Note the exact wording: “Are you sure you want to do this?”, “Please try again,” or a security-check / nonce message in a plugin screen.
- If you never reach a usable login form, use admin login not working first.
- If the failure is an update lock, destination folder, or create-directory error, use update failed errors.
Quick triage map
| What you observe | Likely layer | First useful check |
| Message after leaving an Admin tab open a long time | Expired session or nonce | Sign in again, open a fresh Admin screen, retry once |
| Fails in normal browser; works in a private window | Cookies / extensions | Clear site cookies for this domain; disable extensions; retry |
| Fails after enabling page cache or a CDN on Admin/login | Stale cached Admin HTML | Exclude /wp-admin and /wp-login.php from cache; purge; retry |
| Started after a security / firewall / captcha plugin change | Plugin interference | Staging isolation; see also plugin not working |
| Only on one plugin’s screen; rest of Admin works | That product’s form or conflict | Update or isolate that plugin on staging; retest the same action |
Safe diagnostic order
- Retry from a fresh Admin session. Sign out if needed, sign in again, open the screen from the dashboard (do not reuse an old tab), and repeat the action once. Many failures clear when the token and session match again.
- Test a private window and a second browser. Disable extensions that rewrite pages or block cookies. If a private window works, clear cookies for your site’s domain in the main browser and retry.
- Keep Admin and login pages out of page caching. Page cache, CDN, or host “optimize everything” rules that store
/wp-admin or /wp-login.php HTML can serve an old nonce to a new session. Exclude those paths, purge the cache, and retry the same Admin action. Ask your host to confirm these pages bypass page caching for both signed-in and signed-out requests.
- Check security and firewall plugins. On staging, note which security, captcha, WAF, or “hide login” plugins are active. Temporarily adjust or disable the newest one for a short test, retest the failing action, then restore protection. A successful test with a plugin disabled does not mean you should leave protection off.
- Isolate other plugin or theme conflicts on staging. If the message appears only on one screen, update that plugin/theme first when a trusted update exists. Otherwise disable non-essential plugins briefly and retest the same action, then reactivate one at a time. See plugin not working when isolation points at one product.
- Separate this screen from other install failures. Theme/plugin ZIP uploads that show “The link you followed has expired” can be size-limit or stale-form issues. Use link you followed has expired when that is the exact message. Update-folder collisions belong on update failed errors.
- Retest with protection restored. Restore any security plugins or settings temporarily changed for testing. Keep the Admin and login cache exclusions that fixed the problem. Repeat the original action if it is safe to do so, then complete a second normal Admin task. Confirm both work with protection enabled.
Common causes
- Admin tab or form left open until the nonce or session expired.
- Page cache or CDN serving stale Admin or login HTML with an old token.
- Browser cookies cleared, blocked, or mismatched across
www / HTTPS variants.
- Security, firewall, captcha, or “hide login” plugins altering Admin requests.
- A plugin or theme form that fails its own check, or a conflict that surfaces as this generic screen.
When a $99 one-time fix fits
Request the $99 one-time WordPress fix if you want help on one WordPress site clearing a repeatable “Are you sure you want to do this?” (or “Please try again”) Admin security check: confirming session/cache behavior, coordinating Admin cache exclusions or a host-approved security-plugin adjustment, and verifying the same Admin action succeeds. Paste the exact message, which Admin action triggers it, and when it started. We confirm the scope before work begins. Send credentials only through the private access link provided after your request is accepted.
Full rebuilds, new custom Admin tooling, account-wide host outages, and login lockouts without this security-check screen are outside this offer. Use admin login not working when you cannot authenticate, and plugin not working when one product’s screens fail after isolation.
Related checks
If a fresh session, Admin cache exclusions, and staging isolation still leave the security-check screen, send your host the exact message, the Admin URL or action, the time it started, and whether a private window behaves differently. Suspected compromise needs a security investigation as well as restoring normal Admin actions.