Common causes
- The theme or plugin ZIP is larger than upload_max_filesize or post_max_size
- max_execution_time or max_input_time too low for the upload
- A page or form left open longer than the nonce lifetime (12 to 24 hours)
- Caching serving an old page with an expired nonce to logged-in users
- A security plugin or WAF stripping or blocking the POST data
How to fix it
- Check the upload limits. Go to Media > Add New to see the "Maximum upload file size". If your ZIP is larger, raise upload_max_filesize and post_max_size.
- Raise PHP limits. In php.ini or .user.ini set upload_max_filesize = 128M, post_max_size = 128M, max_execution_time = 300 and max_input_time = 300, then restart PHP-FPM. On cPanel use MultiPHP INI Editor.
- Upload by FTP instead. Unzip the theme or plugin on your computer and upload the folder to wp-content/themes or wp-content/plugins by SFTP. Then activate it from wp-admin.
- Reload the page and try again. If you left the editor open for a long time, reload the page to get a fresh nonce before saving.
- Exclude admin pages from caching. Make sure wp-admin and logged-in users are not served from page cache or a CDN, so forms always have a valid nonce.
PHP limits for large theme or plugin uploads
; php.ini or .user.ini
upload_max_filesize = 128M
post_max_size = 128M
max_execution_time = 300
max_input_time = 300 How to stop it happening again
- Install large themes by SFTP or WP-CLI
- Keep post_max_size at least as large as upload_max_filesize
- Never cache wp-admin or logged-in pages
- Reload long-open editor tabs before saving