Skip to content
Witen

WordPress recovery

Recover WordPress login access

Find the control that blocked your login and follow its fix. Keep SFTP or hosting-panel access as a way back in before you change login protection.

A login ban

Stop retrying and wait for the ban to expire. By default, five failed attempts within five minutes earn a one-hour IP ban; your site may use different limits.

If another administrator can sign in, ask them to review your address under Witen → Firewall → IP Blocklist and add your trusted address under Witen → Firewall → Never-block list. If every visitor shows the same IP, fix your proxy’s client-address setup before you lift the block.

Changing login limits does not remove an existing ban.

A lost authenticator

  1. Sign in with your normal password. When Witen asks for your two-factor code, re-enter your password and use an unused ten-character recovery code. Each code works once.
  2. After signing in, open your user profile, disable the old 2FA setup, and enroll your replacement authenticator. Store the new recovery codes securely.
  3. If you have no recovery code, ask an administrator who can still sign in to reset your 2FA from your user profile.

A site owner with WP-CLI access can reset one verified account. First identify the account, then replace 123 with its user ID:

wp user list --fields=ID,user_login
wp eval 'Witen_Two_Factor::disable(123);'

This removes that account’s Witen 2FA secret and recovery codes. Set up 2FA again right away. On Multisite, user accounts and 2FA enrollment are shared across the network.

A changed login URL

Use the custom login address saved under Witen → Login. If you have lost it, run WP-CLI from your WordPress installation:

wp option delete witen_login_slug
wp rewrite flush

Then open /wp-login.php. For Multisite, add --url=https://your-site.example to each command to select the affected site.

Emergency access through your host

  1. Take a backup through your hosting panel or SFTP.
  2. Rename the witen-blocker folder under your WordPress plugins directory to witen-blocker-disabled. This stops Witen’s PHP login checks; it preserves settings.
  3. Try /wp-login.php. If Apache still blocks access, back up the site’s .htaccess, then remove only the sections between # BEGIN Witen Blocklist / # END Witen Blocklist and, when necessary, # BEGIN Witen Hardening / # END Witen Hardening. Preserve WordPress and other plugins’ sections.
  4. After recovering access, fix the cause, restore the folder name, and review Witen’s settings before reactivating it.

A Warden firewall block

Use your host’s console or an already-open SSH session. Replace the example address with the blocked address:

sudo warden unban 198.51.100.42

Check your trusted-address configuration before reconnecting. Switching Warden to the null backend does not lift an existing ban.

Continue with the Warden guide or WordPress setup guide.