Get a free website with any plan

See how
WORDPRESS

Fixing the wp-login redirect loop

Last updated

IN SHORT

A WordPress wp-login redirect loop occurs when your site cannot confirm your login session. At Flashcloud, fixing it starts with matching your siteurl and home values to your exact domain and HTTPS protocol in wp-config.php or phpMyAdmin. Clearing domain cookies and temporarily disabling plugins isolate the remaining causes.

A wp-login redirect loop means WordPress sends you back to wp-login.php right after you log in, sometimes with ?redirect_to= stacking in the URL until the browser gives up with "too many redirects." The fix is almost always one of three things: a site URL mismatch, a broken cookie domain, or a plugin (usually caching or security) interfering with the login request. Work through them in this order.

Check your site URLs first

WordPress stores two URLs in the database: siteurl and home. If either one doesn't match the domain you're actually visiting (missing www, wrong protocol, leftover staging domain), the login cookie gets set for one URL while the browser requests another, and WordPress can never confirm you're logged in.

  • Open wp-config.php via FTP or the file manager and check for hardcoded WP_HOME or WP_SITEURL constants. If present, confirm they match your actual domain and protocol exactly.
  • If those constants aren't set, check Settings → General in wp-admin, if you can reach it. If the redirect loop blocks admin entirely, update the URLs directly in the database via phpMyAdmin: the wp_options table, rows with option_name of siteurl and home.
  • Make sure both use https://, not http://. A site with SSL issued but URLs still saved as http:// is a common trigger, especially right after a domain migration.

Clear cookies and check the cookie domain

The second most common cause is a stale or mismatched auth cookie. If you recently changed domains, moved from a staging subdomain, or switched between www and non-www, your browser may be holding a login cookie scoped to the wrong host.

  • Clear cookies for your domain specifically (not just cache) and try logging in again in a private/incognito window. If that works, the problem is a stale cookie, and normal users will self-resolve once their browser cookie expires or they clear it.
  • If you're using a multisite-style setup or a plugin that sets COOKIE_DOMAIN in wp-config.php, confirm it matches your actual domain with no typos and no stray leading dot unless you specifically need subdomain-wide cookies.
  • Check that your domain's DNS is fully pointed at your host. A half-migrated domain (some records pointing elsewhere) can cause inconsistent SSL and cookie behavior that looks exactly like a redirect loop.

Disable plugins one at a time

If URLs and cookies check out, a plugin is almost certainly rewriting login requests or blocking the auth cookie from being set. Security and caching plugins are the usual suspects, since both hook into the login process by design.

  • Rename /wp-content/plugins/ to /wp-content/plugins.bak/ via FTP or the file manager, then try logging in again. If it works, a plugin is the cause.
  • Rename the folder back, then disable plugins one at a time from wp-admin (once you're in) or by moving individual plugin folders out of plugins.bak one at a time back into plugins <pre>wp plugin activate plugin-slug-name</pre> <p>If LiteSpeed Cache is active, purge the cache after any plugin change, since a cached version of the login page can mask whether your fix actually worked. Object cache and page cache issues are covered in more depth in <a href="/knowledgebase/article/wordpress-site-health-warnings-and-which-ones-matter">WordPress Site Health warnings and which ones matter</a>.</p> <h3>A note on <code>.htaccess

    Less common, but worth a quick check: a bad redirect rule in .htaccess can catch wp-login.php requests and bounce them before WordPress even loads. Open .htaccess in the file manager and look for any custom rewrite rules above the standard WordPress block (the one starting with # BEGIN WordPress). If you added a redirect rule recently, for example enforcing www or HTTPS, make sure it isn't rewriting the query string in a way that strips or duplicates redirect_to.

    If the white screen shows up instead

    If disabling plugins turns the redirect loop into a blank white page rather than a working login, that's a separate issue with its own fix: see Fixing the WordPress white screen of death. And if the error you're actually seeing mentions the database rather than a redirect, that points to Fixing WordPress database connection errors instead.

    When to open a ticket

    If you've confirmed the site URLs are correct, cleared cookies, disabled every plugin, and checked .htaccess, and the loop still happens, open a ticket from the portal (Support → New ticket). Include the exact URL you're logging in from, whether you've recently changed domains or DNS, and what you've already tried. A real person will look at server-level logs that aren't visible from wp-admin, which can catch edge cases like a caching layer outside WordPress itself.

Common questions

Why does WordPress send me back to the login screen after I log in?

Your site URLs likely do not match your actual domain. Check wp-config.php or the wp_options table in phpMyAdmin to verify siteurl and home use your exact domain and https://. Mismatched cookies or caching plugins also trigger this loop.

How do I turn off plugins if I cannot get into wp-admin?

Rename the /wp-content/plugins/ directory to /wp-content/plugins.bak/ using FTP or the file manager. This disables all plugins so you can test the login screen. Once you are in, restore the folder name and turn them back on one by one.

Why did my login start looping after installing SSL?

Your database URLs still use http:// instead of https://. Update both siteurl and home to https:// in your wp_options table or wp-config.php. Stale browser cookies scoped to the old protocol will also block login attempts until cleared.

Can my .htaccess file break wp-login?

Yes, custom redirect rules placed above the standard WordPress block can intercept login requests. Check .htaccess in your file manager to make sure custom rules do not alter query strings or duplicate the redirect_to parameter.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.