Is this your problem?
- The password reset email never arrives
- "Too many failed login attempts" or a lockout message
- wp-login.php shows a 404 page
- Two-factor codes are no longer accepted
- Your username no longer exists
What usually causes it
How to tell: The reset form says an email was sent, but nothing arrives, even in spam.
How to tell: A message about too many attempts, often with a time limit.
How to tell: wp-login.php shows a 404, and someone installed a "hide login" plugin.
How to tell: You changed phones, or the app was deleted.
How to tell: Your user is missing, or its role is no longer Administrator.
Before you touch anything
- Make sure you have your hosting login. Most ways back in go through the host.
How to fix it, step by step
-
1
Wait out a lockout
Security plugins usually unlock after a set time. If you cannot wait, rename that plugin folder in wp-content/plugins, log in, rename it back and turn it on again.
-
2
Find a moved login page
Rename the hide-login plugin folder and the normal yoursite.com/wp-login.php works again.
-
3
Set a new password with WP-CLI
Many hosts include WP-CLI over SSH. This is the cleanest way to set a password.
wp user list --role=administrator wp user update USERNAME --user_pass="a-long-new-password" -
4
Or with phpMyAdmin
In phpMyAdmin, open the users table (wp_users, or your own prefix), edit your user, set the MD5 function on user_pass and type a new password. WordPress accepts it once and upgrades it to a stronger hash when you log in.
-
5
Get past two-factor
Use a backup code if you saved one. If not, rename the two-factor plugin folder, log in, set it up again on your new phone, and turn it back on.
-
6
Fix email for next time
If the reset email never arrived, the site cannot send mail. Fix that next, or the next lockout will be the same.
Stop and get help if
- Your user is gone, or there are administrators you do not know. Change the hosting password first, then clean the site.
- The database users table looks different from what you expect.
Stop it happening again
- Store the hosting login and backup codes in a password manager.
- Keep one spare administrator account with a strong password.
- Make sure the site can send email.
Questions people ask
How long does a WordPress lockout last?
WordPress itself has no lockout. Security plugins do, and each sets its own time, often 20 minutes to a few hours.
Is MD5 safe to use here?
Only as a one-time step. WordPress replaces it with its own stronger hash the first time you log in.