Ffile2fix
Sign in Get started

How to fix the WordPress login redirect loop

(After entering the correct username and password, wp-login.php reloads and asks you to log in again.)

Your login succeeds, but the browser does not send the auth cookie back on the next request, so WordPress asks you to log in again. The usual cause is a mismatch between the site URL and the URL you are using (http vs https, www vs non-www), which makes the cookie invalid for that address.

Also appears as: wp-login.php?redirect_to=https%3A%2F%2Fexample.com%2Fwp-admin%2F&reauth=1 · Error: Cookies are blocked or not supported by your browser. You must enable cookies to use WordPress. · Login page refreshes with no error message

Common causes

  • WordPress Address and Site Address differ from the URL in the browser (http/https or www)
  • HTTPS behind a proxy or Cloudflare not detected, so secure cookies are not set correctly
  • Page caching or a CDN caching wp-login.php or wp-admin
  • COOKIE_DOMAIN or other cookie constants set incorrectly in wp-config.php
  • A security or login plugin redirecting the login
  • Session or object cache issues after a migration

How to fix it

  1. Clear cookies and try a private window. Delete cookies for the site and test in a private window. Old cookies from a previous domain or protocol often cause the loop.
  2. Make the site URLs match. Check siteurl and home in wp_options. They must match the exact URL you use. Force them in wp-config.php with WP_HOME and WP_SITEURL if you cannot log in.
  3. Fix HTTPS detection behind a proxy. If you use Cloudflare or a load balancer, set Cloudflare SSL to Full (strict) and add the HTTP_X_FORWARDED_PROTO check in wp-config.php so WordPress knows the request is HTTPS.
  4. Exclude login and admin from caching. Make sure wp-login.php, /wp-admin/ and requests with wordpress_logged_in cookies bypass page cache and CDN cache.
  5. Disable plugins by folder rename. Rename wp-content/plugins to plugins-off. If login works, a plugin is the cause; restore the folder and rename plugins one at a time.
  6. Remove custom cookie constants. Comment out COOKIE_DOMAIN, COOKIEPATH or ADMIN_COOKIE_PATH in wp-config.php unless you are sure you need them.

wp-config.php: force matching URLs

define( 'WP_HOME', 'https://www.example.com' );
define( 'WP_SITEURL', 'https://www.example.com' );
// remove or correct this if present:
// define( 'COOKIE_DOMAIN', 'old-domain.com' );

How to stop it happening again

  • Pick one canonical URL and redirect everything else to it
  • Never cache wp-login.php or wp-admin
  • Update site URLs right after migrations
  • Avoid custom cookie constants unless needed

Frequently asked questions

Why does it happen right after moving to HTTPS?

The site URL may still be http, or WordPress may not detect HTTPS behind a proxy. The auth cookie is then set for one scheme and the admin requires the other.

Can I reset the URLs without wp-admin?

Yes. Use WP_HOME and WP_SITEURL in wp-config.php, or run wp option update home and wp option update siteurl with WP-CLI.

Does resetting my password help?

No. The password is correct; the problem is the cookie. Resetting does not fix a URL or caching mismatch.