Locked out of WP site admin

Avatar
  • Answered
I'm unable to log into my Wordpress site admin dashboard. I had logged in successfully to create a new post, published the post, and was locked out afterward. I tried disabling my security plugin from the cPanel file manager, got to the WP standard login screen, entered my credentials, and now get a "too many redirect loops" error message. Any suggestions on what to try next?
Duplicates 1
i keep getting locked out of my site?? WTF!
Avatar
IMH Support Agent 2

Follow the directions in the Locking the WordPress Admin access by IP address.  Try it by one IP address at first.  The instructions on the article walk you through the steps. Once your site is secured to allow only one IP address access, then you just need to wait 15 minutes and then try to login after. We unfortunately cannot make the change for you.

Avatar
Derek Ingram

15mins..??? 

I've been locked out this time for days.

I'm not clever enough to fix this:-(((

Avatar
IMH Support Agent 2

Hi Derek,

Sorry for the frustration with this issue.  I walked over to a systems person and asked for the best way to approach your problem.  The main issue is that your particular site is being attacked by a brute force attack.  I was told that a mod security rule that is blocking access requires about 15 minutes of not being attacked before it will allow access.  The rule cannot be lifted for server security reasons.  He said that you can employ rules in the .htaccess file to prevent access from everything but specific IP addresses to mitigate the attack.  You can do that by following the directions provided in this article:  WordPress wp-login.php Brute Force Attack.  There is a link in that article on how to limit the IP address that can access your site.  It also provides other ways to help prevent future attacks of this nature. I recommend trying Cloudflare as an extra security measure.  The .htaccess change I am recommending can be done through your cPanel File Manager.  I hope that helps to resolve the issue!  If you require further assistance please let us know!

Regards,
Arnel C.

Avatar
Derek Ingram

added /wp/wp-admin

Avatar
Derek Ingram

I have always just keyed in my domain and added /we and a page would load.  Clearly states Unfortunately you will be unable to login to the dashboard until the block expires. My seo people are unable to access either!

Avatar
IMH Support Agent 2

I checked your account for any reported issues and there's nothing indicating an problem.  The last report was in regards to an FTP issue. Can you provide the steps you're taking to access your account?  Are you trying access it using cPanel?  Or are you trying to access an application running on the web server? Any error messages would also help us pin down the cause.  I also recommend that you speak with the live technical support team, as they would have access to server logs that can help determine the cause of this problem.  

Avatar
Derek Ingram

says

WordPress Login Temporarily Disabled.

Attackers bla bla bla.... 

Avatar
IMH Support Agent 2
  • Answered

Hello Derek,

Sorry for the problems with being unable to access your site.  Unfortunately, we can't help you without more details about your account.  If you can provide the domain name that we're hosting we can look to see what's happening.  If you want to handle the issue privately, then please contact our live technical support team via chat/email/phone. 

Avatar
Scott
Hello, Sorry to hear you are having issues with your WordPress login. I am not able to see which domain is having the issue. The "too many redirects" error usually comes from a malformed .htaccess file. You may want to take a look for any conflicting redirects. As for being locked out of the admin, are you simply not able to log in? Have you reset the password via the forgotten password link using your email? Kindest Regards, Scott M