Common causes
- The admin screen was open so long that its nonce expired (nonces last 12-24 hours)
- You logged out and back in, invalidating nonces created in the old session
- A page cache, CDN or object cache served an admin page with someone else's or an old nonce
- A plugin or theme builds forms or links with the wrong nonce action name
- Uploads exceeding post_max_size stripped the nonce field (see 'The link you followed has expired')
- Server clock or salts changed between generating and verifying the nonce
How to fix it
- Reload and retry. Refresh the admin page (not the browser back button) so a fresh nonce is generated, then repeat the action.
- Log out and clear cookies. Log out, clear cookies for the site, log back in and try again. This resets the session the nonce is tied to.
- Exclude admin from caching. Make sure /wp-admin/, admin-ajax.php and pages for logged-in users bypass page cache and CDN caching.
- Find the plugin responsible. If the error appears on a plugin's settings page or button, deactivate plugins one by one; a plugin with a nonce bug will fail consistently on the same action.
- Check upload size if it happens on upload. If it occurs when uploading a theme, plugin or import file, raise post_max_size and upload_max_filesize above the file size.
- Verify the server time. On a VPS ensure NTP is running (timedatectl). Large clock jumps can make freshly generated nonces look expired.
Plugin developers: correct nonce usage
// In the form
wp_nonce_field( 'myplugin_save_settings', 'myplugin_nonce' );
// In the handler
check_admin_referer( 'myplugin_save_settings', 'myplugin_nonce' ); How to stop it happening again
- Never cache pages for logged-in users
- Reload long-idle admin tabs before submitting changes
- Use matching action names in wp_nonce_field and check_admin_referer in custom code