Cannot get into the WordPress dashboard: the six usual causes

·

The site opens, but the admin dashboard does not. Either it asks for the password in an endless loop, or it says the details are wrong when you are sure they are not. These are the causes, from the most common to the rarest, and at the end is what to do when none of them is enough.

1. Wrong password, or wrong user

Start with the obvious, because that is where most cases are. The WordPress user is not your cPanel user or your Meu Interweb one: they are three independent accounts, and people often try the wrong password with total conviction.

1 Use Lost your password? on the sign-in screen. An e-mail arrives with a link to set a new one.
2 If the e-mail never comes, the problem is now the site’s ability to send mail, not the password.
3 With no access to that mailbox, you can still change the password in the database through phpMyAdmin: see databases and phpMyAdmin. In the wp_users table, edit user_pass and pick the MD5 function from the list beside it. Without choosing that function, the password will not work.

2. Locked out for too many attempts

If you run a security plugin, it counts failed attempts and blocks the address for a while. That is a sign it is doing its job, and it is inconvenient when the one blocked is you.

How to recognise it. The site opens normally, but wp-admin refuses even with the right password, and it works from another network, such as mobile data. If so, wait the block out, or disable the plugin by renaming its folder in wp-content/plugins through File Manager.

If what blocked you was the server firewall rather than a plugin, the route is different: how to unblock your IP address.

3. The site address is wrong in the database

This is the one that wastes the most time, because the symptom misleads: wp-admin redirects somewhere else, or loops, or the dashboard opens with no styling at all. It happens after changing domain, or after moving from http to https.

WordPress stores its own address in the database. If what is stored does not match the real address, it redirects to the old one and never reaches the dashboard.

1 Open phpMyAdmin and the site’s database.
2 In the wp_options table, find the siteurl and home rows.
3 Set both to the correct, full address, with https:// and no trailing slash.
The prefix may not be wp_. Many installations use a different one for security, so you see xyz_options instead of wp_options. It is the same table; use whichever is there.

If you would rather not touch the database, you can force both addresses from wp-config.php, with define( 'WP_HOME', 'https://asuaempresa.ao' ); and define( 'WP_SITEURL', 'https://asuaempresa.ao' );. While those lines are there they win, and the fields are locked in the dashboard.

4. Certificate trouble or a redirect loop

If the browser warns that the connection is not secure, or the page says it redirected too many times, the problem is the SSL and not the password. See what an SSL certificate is and why it matters and no padlock on your site.

If you changed domain recently, it may simply be propagation still finishing: how long DNS propagation takes.

5. Browser cache and cookies

Signing in to WordPress relies on cookies. If they are corrupted, the dashboard refuses without explaining why.

Try a private window or another browser. If that gets you in, the site is fine: clear the cache and cookies in your usual browser and try again. If you run a caching plugin, clear its cache too, and make sure the login page is not being cached.

6. Database connection error

If you see Error establishing a database connection, the dashboard is not the issue: the whole site has lost its database. Check in wp-config.php that the database name, user and password match what exists in cPanel, and that the user is added to the database with full privileges. The causes in order are in error establishing a database connection, and direct management in databases and phpMyAdmin.

Getting back in when none of the six is enough

There are three rescue routes, from the gentlest to the bluntest. Take a backup before using the third: how to restore your data.

1 Through the WordPress tool in cPanel. In cPanel, under Domains, there is a WordPress Management tool listing the installations on the account. Each one has a sign-in button that takes you to the dashboard without asking for the WordPress password, because the authorisation comes from cPanel. It is the fastest route and the one that breaks least. From there you can also change the administrator password.
2 Through the database. phpMyAdmin, wp_users table, user_pass field, MD5 function. Also check, in wp_usermeta, that your user has a wp_capabilities row containing administrator: a demoted account signs in and sees nothing.
3 An emergency administrator. Only when the two above fail. Create the folder wp-content/mu-plugins (if it is not there) and, inside it, a file rescue.php with the code below. Sign in with that user and delete the file straight afterwards.

<?php add_action( 'init', function () { if ( ! get_user_by( 'login', 'rescue' ) ) { $id = wp_create_user( 'rescue', 'A-LONG-PASSWORD-OF-YOURS', 'you@asuaempresa.ao' ); ( new WP_User( $id ) )->set_role( 'administrator' ); } } );

That file is an open door for as long as it is there. Anyone who works out the name and password walks in as an administrator, and a file in mu-plugins cannot be switched off from the dashboard. Use a long password, sign in, change your own password, delete rescue.php, and only then delete the rescue user.

The recovery e-mail that never arrives

This is a case of its own and it is solved elsewhere. The «lost your password» e-mail leaves the site itself. If the site cannot send mail, there is no new password. Check three things: that the address in Settings › General is still yours, that the message did not land in spam, and that the site can actually send. See why your e-mail is not sending or receiving, and above all make WordPress send through SMTP, which is the permanent cure for this case.

Lost the second factor? If you put two-step authentication on WordPress and lost the phone, the code cannot be recovered: disable the plugin by renaming its folder in wp-content/plugins, sign in, and set it up again. That is WordPress; the second factor on Meu Interweb is turned on and off somewhere else: two-step authentication.

If none of it works

Restore an earlier backup: how to restore your data. And if the dashboard opens but throws a critical error or a white screen, that is a different article: common WordPress errors.

What we can do for you. We do not hold your WordPress password: it is yours and it never passed through us. What we do is confirm the server, the SSL and the database are healthy on our side, unblock your address if it was the firewall, and help you reach the dashboard through the cPanel tool. See how far our support goes.

Been through all of it and still cannot get in?

Open a request

SEE ALSO

Support Policy: what our support covers

Password generator

WordPress hosting

RECOMMENDED PRODUCT

WordPress hosting

One-click install, updates handled, and speed that holds up. from 5.940,00 Kz/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?