Common causes
- WordPress Address and Site Address differ from the URL in the browser (http/https or www)
- HTTPS behind a proxy or Cloudflare not detected, so secure cookies are not set correctly
- Page caching or a CDN caching wp-login.php or wp-admin
- COOKIE_DOMAIN or other cookie constants set incorrectly in wp-config.php
- A security or login plugin redirecting the login
- Session or object cache issues after a migration
How to fix it
- Clear cookies and try a private window. Delete cookies for the site and test in a private window. Old cookies from a previous domain or protocol often cause the loop.
- Make the site URLs match. Check siteurl and home in wp_options. They must match the exact URL you use. Force them in wp-config.php with WP_HOME and WP_SITEURL if you cannot log in.
- Fix HTTPS detection behind a proxy. If you use Cloudflare or a load balancer, set Cloudflare SSL to Full (strict) and add the HTTP_X_FORWARDED_PROTO check in wp-config.php so WordPress knows the request is HTTPS.
- Exclude login and admin from caching. Make sure wp-login.php, /wp-admin/ and requests with wordpress_logged_in cookies bypass page cache and CDN cache.
- Disable plugins by folder rename. Rename wp-content/plugins to plugins-off. If login works, a plugin is the cause; restore the folder and rename plugins one at a time.
- Remove custom cookie constants. Comment out COOKIE_DOMAIN, COOKIEPATH or ADMIN_COOKIE_PATH in wp-config.php unless you are sure you need them.
wp-config.php: force matching URLs
define( 'WP_HOME', 'https://www.example.com' );
define( 'WP_SITEURL', 'https://www.example.com' );
// remove or correct this if present:
// define( 'COOKIE_DOMAIN', 'old-domain.com' ); How to stop it happening again
- Pick one canonical URL and redirect everything else to it
- Never cache wp-login.php or wp-admin
- Update site URLs right after migrations
- Avoid custom cookie constants unless needed