Common causes
- siteurl and home differ in www vs non-www or http vs https
- Site moved to HTTPS behind a proxy, CDN or load balancer without telling WordPress the request is secure
- A page cache or CDN caching wp-login.php or wp-admin responses
- Stale or conflicting cookies from an old domain
- A security or redirect plugin forcing a URL that conflicts with WordPress settings
- COOKIE_DOMAIN or ADMIN_COOKIE_PATH set incorrectly in wp-config.php
How to fix it
- Clear cookies for the site. Delete all cookies for the domain (including www and non-www variants) or test in a private window. Stale wordpress_logged_in_ cookies are a frequent trigger.
- Make siteurl and home match the real URL. Check both values with wp option get siteurl and wp option get home, or in wp_options via phpMyAdmin. Both must use the exact scheme and host you browse to.
- Force the URLs in wp-config.php. Temporarily define WP_HOME and WP_SITEURL with the correct https URL to override the database values while you fix things.
- Tell WordPress about HTTPS behind a proxy. If Cloudflare, a load balancer or Nginx proxy terminates SSL, WordPress sees plain HTTP and loops. Set $_SERVER['HTTPS'] = 'on' when the X-Forwarded-Proto header is https, but only if your proxy sets that header.
- Exclude login and admin from caching. In your caching plugin, host cache and CDN, bypass /wp-login.php, /wp-admin/ and requests with wordpress_logged_in cookies.
- Disable plugins to rule out conflicts. Rename wp-content/plugins temporarily. If you can log in, re-enable plugins one by one, starting with security, SSL and redirect plugins.
wp-config.php (above 'That's all, stop editing!')
define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );
// Only behind a trusted proxy that sets this header
if ( isset( $_SERVER['HTTP_X_FORWARDED_PROTO'] )
&& $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https' ) {
$_SERVER['HTTPS'] = 'on';
} How to stop it happening again
- Pick one canonical host (www or not) and redirect the other at the server level
- Never cache wp-admin or wp-login.php at any layer
- Update siteurl and home together when switching to HTTPS