WordPress recovery
Recover WordPress login access
Find the control that blocked your login and follow its fix. Keep SFTP or hosting-panel access as a way back in before you change login protection.
A login ban
Stop retrying and wait for the ban to expire. By default, five failed attempts within five minutes earn a one-hour IP ban; your site may use different limits.
If another administrator can sign in, ask them to review your address under Witen → Firewall → IP Blocklist and add your trusted address under Witen → Firewall → Never-block list. If every visitor shows the same IP, fix your proxy’s client-address setup before you lift the block.
Changing login limits does not remove an existing ban.
A lost authenticator
- Sign in with your normal password. When Witen asks for your two-factor code, re-enter your password and use an unused ten-character recovery code. Each code works once.
- After signing in, open your user profile, disable the old 2FA setup, and enroll your replacement authenticator. Store the new recovery codes securely.
- If you have no recovery code, ask an administrator who can still sign in to reset your 2FA from your user profile.
A site owner with WP-CLI access can reset one verified account. First identify the account, then replace 123 with its user ID:
wp user list --fields=ID,user_login
wp eval 'Witen_Two_Factor::disable(123);'This removes that account’s Witen 2FA secret and recovery codes. Set up 2FA again right away. On Multisite, user accounts and 2FA enrollment are shared across the network.
A changed login URL
Use the custom login address saved under Witen → Login. If you have lost it, run WP-CLI from your WordPress installation:
wp option delete witen_login_slug
wp rewrite flushThen open /wp-login.php. For Multisite, add --url=https://your-site.example to each command to select the affected site.
Emergency access through your host
- Take a backup through your hosting panel or SFTP.
- Rename the
witen-blockerfolder under your WordPress plugins directory towiten-blocker-disabled. This stops Witen’s PHP login checks; it preserves settings. - Try
/wp-login.php. If Apache still blocks access, back up the site’s.htaccess, then remove only the sections between# BEGIN Witen Blocklist/# END Witen Blocklistand, when necessary,# BEGIN Witen Hardening/# END Witen Hardening. Preserve WordPress and other plugins’ sections. - After recovering access, fix the cause, restore the folder name, and review Witen’s settings before reactivating it.
A Warden firewall block
Use your host’s console or an already-open SSH session. Replace the example address with the blocked address:
sudo warden unban 198.51.100.42Check your trusted-address configuration before reconnecting. Switching Warden to the null backend does not lift an existing ban.
Continue with the Warden guide or WordPress setup guide.