How to Regain Access to Your WordPress Site When Locked Out by Wordfence
Content
Getting locked out of your WordPress admin dashboard is a common and frustrating experience, especially when it's your own security plugin preventing access. Based on community reports, this often happens due to Two-Factor Authentication (2FA) issues, forgotten recovery codes, or the firewall's Brute Force Protection feature. This guide will walk you through the most effective methods to regain control of your site.
Why Am I Locked Out?
Lockouts typically occur for a few key reasons:
- Two-Factor Authentication (2FA) Problems: Losing access to your authenticator app (e.g., Google Authenticator) or its generated codes is a frequent cause. This can happen if you get a new phone, delete the app, or the codes simply stop syncing.
- Brute Force Protection: The Wordfence Security firewall may temporarily limit access after multiple failed login attempts, even if they were your own. This can sometimes block legitimate administrators.
- reCAPTCHA Conflicts: Enabling reCAPTCHA, especially on a custom login page (from a theme, membership plugin, or page builder), can cause expiration errors and prevent successful logins.
- Plugin or Theme Conflicts: A recent update to another plugin or your theme can interfere with Wordfence's login security features, causing unexpected behavior.
How to Regain Access: Step-by-Step Solutions
Method 1: The Universal Fix – Rename the Plugin Folder (FTP/SFTP)
This is the most reliable method to bypass Wordfence entirely and is recommended if you cannot log in at all. It deactivates the plugin without deleting any of its settings.
- Access your website's files using an FTP/SFTP client (like FileZilla) or the file manager in your web hosting control panel (e.g., cPanel).
- Navigate to the
/wp-content/plugins/directory. - Find the folder named
wordfence. - Rename this folder to
wordfence.bakorwordfence_bak. - Now, try to access your WordPress login page (yoursite.com/wp-admin). You should be able to log in without any 2FA or firewall restrictions.
- After successfully logging in, you can rename the folder back to
wordfenceto reactivate the plugin. You will then need to troubleshoot the specific issue that caused the lockout (see below).
Method 2: If You're Receiving a "Blocked" Message
If you see a message like "Your access to this site has been temporarily limited," you can often use the built-in unlock email feature.
- On the blocking page, enter your administrator email address and click the button to send an unlock email.
- Important: This only works if the email is associated with a valid administrator account on the site.
- Check your inbox for the unlock email and follow the instructions. If you do not receive the email, check your spam folder or proceed to Method 1.
After You Regain Access: Troubleshooting the Root Cause
Simply reactivating Wordfence will likely cause the problem to return. Once you're back in your dashboard, follow these steps to fix the underlying issue.
For 2FA Issues:
- Go to WordPress Admin > Users > Your Profile.
- In the Wordfence Login Security section, deactivate and then reactivate 2FA for your account.
- Crucially: When you set it up again, make sure to download and safely store your new recovery codes. These are your lifeline if you lose your authenticator app again.
For reCAPTCHA or Login Problems:
- Ensure you are using the default WordPress login page (yoursite.com/wp-login.php). The Wordfence Security team states that their 2FA and reCAPTCHA are designed for default WordPress and WooCommerce login pages only. Custom login pages from themes or other plugins are a common source of conflict.
- If you use WooCommerce, go to Wordfence > Login Security > Settings and ensure "WooCommerce integration" is enabled.
- Temporarily disable reCAPTCHA in Wordfence > Login Security > Settings to see if that resolves the immediate problem.
For Firewall (Brute Force) Lockouts:
- Go to Wordfence > Blocking to see if your IP address is listed. If it is, you can remove the block manually.
- Review your settings in Wordfence > All Options > Brute Force Protection. You may want to adjust the lockout time or the number of failed attempts allowed, especially on development sites.
When to Suspect a Conflict
If the problem started after updating a plugin, theme, or WordPress itself, a conflict is likely. To test this:
- Switch to a default WordPress theme (like Twenty Twenty-Four).
- Disable all other plugins except Wordfence.
- Try to log out and log back in. If it works, reactivate your plugins and theme one by one, testing after each, to identify the culprit.
By following these steps, you can quickly resolve most lockout scenarios and configure Wordfence Security to protect your site without accidentally locking yourself out.
Related Support Threads Support
-
I am lock out of my admin websitehttps://wordpress.org/support/topic/i-am-lock-out-of-my-admin-website/
-
[NSFW] can’t login with 2FA or Recaptcha on wordpresshttps://wordpress.org/support/topic/cant-login-with-2fa-or-recaptcha-on-wordpress/
-
I cannot log in Error with wfcongi does not existhttps://wordpress.org/support/topic/i-cannot-log-in-error-with-wfcongi-does-not-exist/
-
Need to change billing infohttps://wordpress.org/support/topic/need-to-change-billing-info/
-
not able to login even after giving right username and passwhttps://wordpress.org/support/topic/not-able-to-login-even-after-giving-right-username-and-passw/
-
Ubable to log in to my website administratorhttps://wordpress.org/support/topic/ubable-to-log-in-to-my-website-administrator/
-
Locked out of admin accounthttps://wordpress.org/support/topic/locked-out-of-admin-account-2/
-
Unable to login or receive reset password emailhttps://wordpress.org/support/topic/unable-to-login-or-receive-reset-password-email/
-
Locked out–Emergency!!!https://wordpress.org/support/topic/locked-out-emergency/
-
Cant require a new password/Locked outhttps://wordpress.org/support/topic/cant-require-a-new-password-locked-out/
-
Bughttps://wordpress.org/support/topic/bug-436/
-
I can no longer access my site as an admin due to 2FA :(https://wordpress.org/support/topic/i-can-no-longer-access-my-site-as-an-admin-due-to-2fa/
-
Locked Out of My Websitehttps://wordpress.org/support/topic/locked-out-of-my-website-16/
-
Wordfence loginhttps://wordpress.org/support/topic/wordfence-login-2/
-
Admin recovery suggestionhttps://wordpress.org/support/topic/admin-recovery-suggestion/
-
Wordfence active, 2FA active, but hackers inside again!?https://wordpress.org/support/topic/wordfence-active-2fa-active-but-hackers-inside-again/
-
Log in page gray and not working. Can’t log in nowhttps://wordpress.org/support/topic/log-in-page-gray-and-not-working-cant-log-in-now/
-
Not getting 2FA notification. Unable to access websitehttps://wordpress.org/support/topic/not-getting-2fa-notification-unable-to-access-website/
-
Access recoveryhttps://wordpress.org/support/topic/access-recovery/
-
Locked out of WP adminhttps://wordpress.org/support/topic/locked-out-of-wp-admin-19/
-
login failedhttps://wordpress.org/support/topic/login-failed-31/
-
Lost MFA can not loginhttps://wordpress.org/support/topic/lost-mfa-can-not-login/
-
ERROR: An error was encountered while trying to authenticate. Please try again.https://wordpress.org/support/topic/error-an-error-was-encountered-while-trying-to-authenticate-please-try-again-17/
-
CAPTCHA EXPIRED problemhttps://wordpress.org/support/topic/captcha-expired-problem/
-
Cant get into wordfence without 2fahttps://wordpress.org/support/topic/cant-get-into-wordfence-without-2fa/
-
unable to log inhttps://wordpress.org/support/topic/unable-to-log-in-67/
-
Is there someone who can de-activate wordfence for me on e particular sitehttps://wordpress.org/support/topic/is-there-someone-who-can-de-activate-wordfence-for-me-on-e-particular-site/
-
Your access to this site has been temporarily limited by the site ownerhttps://wordpress.org/support/topic/your-access-to-this-site-has-been-temporarily-limited-by-the-site-owner-17/
-
Alterar senha adminhttps://wordpress.org/support/topic/alterar-senha-admin/
-
locked out and can’t set uphttps://wordpress.org/support/topic/locked-out-and-cant-set-up/
-
Não estou conseguindo entrar no meu wordfencehttps://wordpress.org/support/topic/nao-estou-conseguindo-entrar-no-meu-wordfence/
-
I have lost my email accounthttps://wordpress.org/support/topic/i-have-lost-my-email-account/
-
Reactivate Wordfence via cPanel File Manager – critical error on this websitehttps://wordpress.org/support/topic/reactivate-wordfence-via-cpanel-file-manager-critical-error-on-this-website/
-
New admin locked outhttps://wordpress.org/support/topic/new-admin-locked-out/