You’re in the middle of editing a WordPress post when suddenly a login popup appears: “Your session has expired. Please log in to continue where you left off.” You log in, only to be sent straight back to the login screen.

It’s frustrating—and if you haven’t saved your work, it can also mean losing important changes.

The good news is that this error is usually caused by cookies, incorrect URL settings, caching, or a plugin conflict. In this guide, we’ll explain why the WordPress “Your Session Has Expired” error happens and walk you through the most effective ways to fix it, starting with the simplest solutions.

What Causes the “Session Has Expired” Error?

WordPress uses cookies to keep you logged in and verify your identity as you move between pages. If those cookies are missing, corrupted, blocked, or no longer valid, WordPress may log you out and display the session-expired message.

Common causes include:

  • Corrupted or outdated browser cookies and cache
  • A mismatch between the WordPress Address and Site Address, such as http vs. https or www vs. non-www
  • Caching plugins or CDNs caching login and admin pages
  • Plugin or theme conflicts
  • Security plugins or firewalls interfering with login cookies
  • Incorrect cookie settings in wp-config.php
  • An inaccurate server clock
  • PHP or server settings that cause sessions to expire unexpectedly

Fix 1: Clear Your Browser Cookies and Cache

The easiest place to start is your browser. Corrupted or outdated cookies can prevent WordPress from recognizing your login session correctly.

  1. Open your browser settings and clear cookies and cached files for your website’s domain.
  2. Close and reopen the browser.
  3. Visit your WordPress login page and sign in again.
READ
How to Check if Your Webcam or Microphone Is Being Accessed Without Permission

You can also try opening your website in an incognito or private window. If the problem disappears there, a browser extension—such as an ad blocker, privacy tool, or security extension—could be interfering with WordPress cookies.

Fix 2: Check Your WordPress and Site URLs

An incorrect or inconsistent website URL is one of the most common causes of WordPress login loops and session problems.

Go to Settings → General and check the following:

  • WordPress Address (URL)
  • Site Address (URL)

Both URLs should match your actual website configuration, including the correct https:// protocol and whether you’re using www or a non-www domain.

For example:

https://example.com

and

https://www.example.com

should not be mixed unless your WordPress installation is specifically configured that way.

Can’t Access the WordPress Dashboard?

If you’re locked out and can’t access Settings → General, you can define the URLs manually in wp-config.php.

Add the following lines above the line that says That's all, stop editing!:

define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');

Replace yourdomain.com with your actual domain.

Also make sure your website consistently redirects to one version of the domain. Switching between HTTP and HTTPS or between www and non-www can cause WordPress authentication cookies to become invalid.

Fix 3: Exclude WordPress Login and Admin Pages From Caching

Caching can also cause session problems if a cached version of a login or administrator page is served to your browser.

If you’re using a caching plugin such as WP Rocket, W3 Total Cache, or LiteSpeed Cache, make sure logged-in users and the WordPress admin area are excluded from caching. These exclusions are normally enabled by default, but it’s worth checking.

READ
Is Your Smart TV Really Spying on You? The Truth About TV Tracking

If you’re using Cloudflare or another CDN, make sure caching is bypassed for:

/wp-admin/*
/wp-login.php

After making changes, clear all caches, including your WordPress caching plugin, server cache, and CDN cache.

Fix 4: Deactivate Plugins to Find a Conflict

A problematic plugin can interfere with WordPress authentication and session cookies. Caching, security, membership, and login-related plugins are particularly worth checking.

If you can access the dashboard:

  1. Go to Plugins → Installed Plugins.
  2. Deactivate all plugins.
  3. Try logging in and working in WordPress again.
  4. If the problem disappears, reactivate your plugins one at a time.
  5. Test WordPress after activating each plugin until the problem returns.

The last plugin you activated is likely responsible.

Can’t Log In?

If you can’t access the WordPress dashboard, connect to your website using FTP or your hosting provider’s file manager.

Go to:

/wp-content/

and temporarily rename the plugins folder to something such as:

plugins_old

Then try logging in again.

If the problem disappears, rename the folder back to plugins and investigate the plugins individually.

You can also temporarily switch to a default WordPress theme, such as Twenty Twenty-Four, to determine whether your active theme is causing the problem.

Fix 5: Check Your Security Plugin Settings

Security plugins such as Wordfence, Solid Security, and All In One WP Security can sometimes interfere with authentication if their login or session settings are too restrictive.

Check for settings related to:

  • Automatic logout
  • Login lockouts
  • IP blocking
  • Session expiration
  • Two-factor authentication
  • Login security rules
READ
How to Check if Your Webcam or Microphone Is Being Accessed Without Permission

Temporarily relaxing these settings can help identify whether the security plugin is responsible.

Once you’ve identified the cause, restore the security settings and use reasonable session and login limits. Don’t leave important security protections disabled unnecessarily.

Incorrect cookie definitions can prevent WordPress from maintaining a valid login session.

Open wp-config.php and look for settings such as:

COOKIE_DOMAIN
COOKIEPATH
SITECOOKIEPATH

If these have been manually configured, make sure their values are correct. In most WordPress installations, these constants don’t need to be defined manually.

Regenerate WordPress Security Keys

If you suspect that old or compromised authentication cookies are causing problems, you can regenerate your WordPress security keys and salts.

WordPress provides an official generator that creates new authentication keys. Replace the existing key and salt values in wp-config.php with the newly generated ones.

Be aware that changing these values will log out all currently logged-in users.

This can be useful if you suspect that an attacker may have obtained a valid authentication cookie.

Fix 7: Check Your Server Time and PHP Settings

WordPress relies on timestamps when validating authentication cookies. If your server’s clock is significantly incorrect, cookies can behave as though they have already expired.

Ask your hosting provider to confirm that the server’s time is accurate.

You should also check your WordPress timezone under:

Settings → General → Timezone

If the problem continues, ask your hosting provider to review relevant PHP and server settings, including:

  • session.gc_maxlifetime
  • PHP session configuration
  • Object caching
  • Redis or Memcached configuration
  • Server-level caching
READ
The Best DNS Servers: Free vs. Paid

A misconfigured object cache can sometimes cause unexpected authentication behavior.

Fix 8: Extend the WordPress Login Session

If WordPress logs you out frequently even though everything else is working correctly, make sure you select Remember Me when logging in.

By default, WordPress uses different authentication-cookie durations depending on whether the user chooses to be remembered.

If you need to customize the duration, you can add a filter to your theme’s functions.php file or, preferably, a small custom plugin:

add_filter('auth_cookie_expiration', function($expiration, $user_id, $remember) {
    return $remember ? 30 * DAY_IN_SECONDS : 2 * DAY_IN_SECONDS;
}, 10, 3);

This example keeps remembered users logged in for up to 30 days.

However, longer sessions come with a security tradeoff. Avoid extending login sessions unnecessarily, particularly on shared or public computers.

Fix 9: Regenerate .htaccess or Reinstall WordPress Core

If none of the previous solutions work, corrupted configuration or WordPress core files could be contributing to the problem.

Regenerate .htaccess

First, create a backup of your existing .htaccess file.

Then rename it to:

.htaccess_old

Log in to WordPress and go to:

Settings → Permalinks

Click Save Changes.

WordPress will generate a new .htaccess file.

Reinstall WordPress Core

You can also reinstall the WordPress core files by going to:

Dashboard → Updates

and selecting Re-install version if the option is available.

This replaces WordPress core files without removing your posts, pages, plugins, themes, or media.

How to Prevent the Error in the Future

Once you’ve fixed the problem, a few simple practices can help prevent it from happening again:


Buy ExpressVPN with PayPal or Credit Card
  • Keep WordPress, plugins, and themes updated.
  • Use one consistent canonical URL for your website.
  • Always use HTTPS.
  • Exclude logged-in users and WordPress admin pages from caching.
  • Avoid using multiple plugins that perform overlapping caching or security functions.
  • Keep your server’s time accurate.
  • Save important drafts regularly.
  • Make sure WordPress autosave is working properly.
  • Use reliable hosting with properly configured PHP and server settings.
READ
How to Check if Your Webcam or Microphone Is Being Accessed Without Permission

A Note About Security

Repeated or unexpected logouts aren’t necessarily a sign of a security breach, but they shouldn’t always be ignored.

If you suddenly start getting logged out without changing anything, check your website for:

  • Unknown administrator accounts
  • Suspicious login activity
  • Unexpected plugin or theme changes
  • Unfamiliar files
  • Recent security alerts

Change administrator passwords if necessary and scan the website with a reputable security plugin.

If you believe an authentication cookie may have been compromised, regenerating WordPress security keys, as described earlier, will invalidate existing login sessions.

The WordPress “Your Session Has Expired” error is usually caused by a problem with cookies, website URLs, caching, or a plugin conflict. In most cases, you can fix it by clearing your browser cookies, checking your WordPress URLs, excluding the login area from caching, or identifying a conflicting plugin.

If the problem continues after you’ve worked through these steps, your hosting provider can check server-level configuration, PHP settings, object caching, and server time to identify the underlying issue.

Advertisement