Ffile2fix
Sign in Get started

How to fix "The link you followed has expired" in WordPress

The link you followed has expired. Please try again.

WordPress could not verify the request's security token (nonce). When uploading a theme or plugin, the real cause is almost always that the file was bigger than post_max_size, so PHP dropped the whole form including the token. It can also happen when a page was left open long enough for the nonce to expire.

Also appears as: The link you followed has expired. (when uploading a theme or plugin ZIP) · The link you followed has expired after saving a page or settings · Are you sure you want to do this? Please try again.

Common causes

  • The theme or plugin ZIP is larger than upload_max_filesize or post_max_size
  • max_execution_time or max_input_time too low for the upload
  • A page or form left open longer than the nonce lifetime (12 to 24 hours)
  • Caching serving an old page with an expired nonce to logged-in users
  • A security plugin or WAF stripping or blocking the POST data

How to fix it

  1. Check the upload limits. Go to Media > Add New to see the "Maximum upload file size". If your ZIP is larger, raise upload_max_filesize and post_max_size.
  2. Raise PHP limits. In php.ini or .user.ini set upload_max_filesize = 128M, post_max_size = 128M, max_execution_time = 300 and max_input_time = 300, then restart PHP-FPM. On cPanel use MultiPHP INI Editor.
  3. Upload by FTP instead. Unzip the theme or plugin on your computer and upload the folder to wp-content/themes or wp-content/plugins by SFTP. Then activate it from wp-admin.
  4. Reload the page and try again. If you left the editor open for a long time, reload the page to get a fresh nonce before saving.
  5. Exclude admin pages from caching. Make sure wp-admin and logged-in users are not served from page cache or a CDN, so forms always have a valid nonce.

PHP limits for large theme or plugin uploads

; php.ini or .user.ini
upload_max_filesize = 128M
post_max_size = 128M
max_execution_time = 300
max_input_time = 300

How to stop it happening again

  • Install large themes by SFTP or WP-CLI
  • Keep post_max_size at least as large as upload_max_filesize
  • Never cache wp-admin or logged-in pages
  • Reload long-open editor tabs before saving

Frequently asked questions

Why does WordPress show this instead of a size error?

When the upload is too big, PHP discards all POST data, including the nonce. WordPress only sees a missing nonce and shows this generic message.

Can I add the limits to .htaccess?

Only if PHP runs as an Apache module. On PHP-FPM, php_value lines are ignored or cause a 500 error; use .user.ini or the host's PHP settings instead.

How long does a WordPress nonce last?

By default a nonce is valid for 12 to 24 hours. After that, forms using it fail until the page is reloaded.