A wp-login redirect loop means WordPress sends you back to wp-login.php right after you log in, sometimes with ?redirect_to= stacking in the URL until the browser gives up with "too many redirects." The fix is almost always one of three things: a site URL mismatch, a broken cookie domain, or a plugin (usually caching or security) interfering with the login request. Work through them in this order.
Check your site URLs first
WordPress stores two URLs in the database: siteurl and home. If either one doesn't match the domain you're actually visiting (missing www, wrong protocol, leftover staging domain), the login cookie gets set for one URL while the browser requests another, and WordPress can never confirm you're logged in.
- Open
wp-config.phpvia FTP or the file manager and check for hardcodedWP_HOMEorWP_SITEURLconstants. If present, confirm they match your actual domain and protocol exactly. - If those constants aren't set, check Settings → General in wp-admin, if you can reach it. If the redirect loop blocks admin entirely, update the URLs directly in the database via phpMyAdmin: the
wp_optionstable, rows withoption_nameofsiteurlandhome. - Make sure both use
https://, nothttp://. A site with SSL issued but URLs still saved ashttp://is a common trigger, especially right after a domain migration.
Clear cookies and check the cookie domain
The second most common cause is a stale or mismatched auth cookie. If you recently changed domains, moved from a staging subdomain, or switched between www and non-www, your browser may be holding a login cookie scoped to the wrong host.
- Clear cookies for your domain specifically (not just cache) and try logging in again in a private/incognito window. If that works, the problem is a stale cookie, and normal users will self-resolve once their browser cookie expires or they clear it.
- If you're using a multisite-style setup or a plugin that sets
COOKIE_DOMAINinwp-config.php, confirm it matches your actual domain with no typos and no stray leading dot unless you specifically need subdomain-wide cookies. - Check that your domain's DNS is fully pointed at your host. A half-migrated domain (some records pointing elsewhere) can cause inconsistent SSL and cookie behavior that looks exactly like a redirect loop.
Disable plugins one at a time
If URLs and cookies check out, a plugin is almost certainly rewriting login requests or blocking the auth cookie from being set. Security and caching plugins are the usual suspects, since both hook into the login process by design.
- Rename
/wp-content/plugins/to/wp-content/plugins.bak/via FTP or the file manager, then try logging in again. If it works, a plugin is the cause. - Rename the folder back, then disable plugins one at a time from wp-admin (once you're in) or by moving individual plugin folders out of
plugins.bakone at a time back intoplugins <pre>wp plugin activate plugin-slug-name</pre> <p>If LiteSpeed Cache is active, purge the cache after any plugin change, since a cached version of the login page can mask whether your fix actually worked. Object cache and page cache issues are covered in more depth in <a href="/knowledgebase/article/wordpress-site-health-warnings-and-which-ones-matter">WordPress Site Health warnings and which ones matter</a>.</p> <h3>A note on <code>.htaccessLess common, but worth a quick check: a bad redirect rule in
.htaccesscan catchwp-login.phprequests and bounce them before WordPress even loads. Open.htaccessin the file manager and look for any custom rewrite rules above the standard WordPress block (the one starting with# BEGIN WordPress). If you added a redirect rule recently, for example enforcingwwwor HTTPS, make sure it isn't rewriting the query string in a way that strips or duplicatesredirect_to.If the white screen shows up instead
If disabling plugins turns the redirect loop into a blank white page rather than a working login, that's a separate issue with its own fix: see Fixing the WordPress white screen of death. And if the error you're actually seeing mentions the database rather than a redirect, that points to Fixing WordPress database connection errors instead.
When to open a ticket
If you've confirmed the site URLs are correct, cleared cookies, disabled every plugin, and checked
.htaccess, and the loop still happens, open a ticket from the portal (Support → New ticket). Include the exact URL you're logging in from, whether you've recently changed domains or DNS, and what you've already tried. A real person will look at server-level logs that aren't visible from wp-admin, which can catch edge cases like a caching layer outside WordPress itself.