Ffile2fix
Sign in Get started

How to fix "Are you sure you want to do this?" in WordPress

Are you sure you want to do this? Please try again.

Admin actions in WordPress carry a nonce, a short-lived token tied to your user session and the action. When check_admin_referer fails the request is blocked with this message (newer versions reword it to 'The link you followed has expired').

Also appears as: Are you sure you want to do this? · Something went wrong. The link you followed has expired. (current WordPress wording) · Nonce verification failed / invalid nonce (plugin admin action)

Common causes

  • The admin screen was open so long that its nonce expired (nonces last 12-24 hours)
  • You logged out and back in, invalidating nonces created in the old session
  • A page cache, CDN or object cache served an admin page with someone else's or an old nonce
  • A plugin or theme builds forms or links with the wrong nonce action name
  • Uploads exceeding post_max_size stripped the nonce field (see 'The link you followed has expired')
  • Server clock or salts changed between generating and verifying the nonce

How to fix it

  1. Reload and retry. Refresh the admin page (not the browser back button) so a fresh nonce is generated, then repeat the action.
  2. Log out and clear cookies. Log out, clear cookies for the site, log back in and try again. This resets the session the nonce is tied to.
  3. Exclude admin from caching. Make sure /wp-admin/, admin-ajax.php and pages for logged-in users bypass page cache and CDN caching.
  4. Find the plugin responsible. If the error appears on a plugin's settings page or button, deactivate plugins one by one; a plugin with a nonce bug will fail consistently on the same action.
  5. Check upload size if it happens on upload. If it occurs when uploading a theme, plugin or import file, raise post_max_size and upload_max_filesize above the file size.
  6. Verify the server time. On a VPS ensure NTP is running (timedatectl). Large clock jumps can make freshly generated nonces look expired.

Plugin developers: correct nonce usage

// In the form
wp_nonce_field( 'myplugin_save_settings', 'myplugin_nonce' );

// In the handler
check_admin_referer( 'myplugin_save_settings', 'myplugin_nonce' );

How to stop it happening again

  • Never cache pages for logged-in users
  • Reload long-idle admin tabs before submitting changes
  • Use matching action names in wp_nonce_field and check_admin_referer in custom code

Frequently asked questions

Is this error a security problem?

No, it is the security feature working. WordPress blocked a request it could not verify, which protects you from cross-site request forgery.

Why do I see 'The link you followed has expired' instead?

Current WordPress versions show that wording for the same nonce failure. Older versions and some plugins still use 'Are you sure you want to do this?'.

Changing salts logged everyone out. Is that related?

Yes. Nonces and cookies are derived from the salts in wp-config.php, so changing them invalidates all existing sessions and nonces. Everyone just needs to log in again.