WordPress normally keeps you logged in while you manage your website, unless the session expires or the login cookies become invalid. If WordPress repeatedly logs you out, the cause is usually related to cookies, cache, browser settings, security plugins, or a mismatch between the website address settings.
This article explains the most common reasons why WordPress may keep logging you out and what to check before contacting support.
Table of Contents
Why WordPress login sessions expire
When you log in to WordPress, the website stores a login session in your browser using cookies. These cookies help WordPress recognize that you are already authenticated.
If the cookie cannot be saved, becomes invalid, or no longer matches the website address, WordPress may ask you to log in again. This can happen even if your username and password are correct.
Common causes
1. The WordPress Address and Site Address do not match
WordPress uses two important address settings:
- WordPress Address
- Site Address
If one uses http:// and the other uses https://, or if one uses www and the other does not, WordPress cookies may not match correctly.
For example, these are treated as different addresses:
https://example.com
https://www.example.com
The same applies to:
http://example.com
https://example.com
Both WordPress address settings should usually use the same version of the domain.
2. Browser cookies are blocked or cleared
WordPress needs cookies to keep your session active.
If your browser blocks cookies, clears them automatically, or runs in a strict privacy mode, WordPress may not be able to keep you logged in.
This can also happen when using browser extensions that block tracking, cookies, or scripts.
3. Cached login or admin pages
Caching is useful for public website pages, but WordPress admin pages should not be cached.
If the login page or admin area is cached incorrectly, WordPress may serve an outdated session page. This can cause repeated logouts, failed redirects, or login loops.
Caching plugins, server cache, browser cache, or CDN cache can all affect this behavior.
4. Security plugin settings
Some security plugins automatically log users out after a short period of inactivity. Others may invalidate sessions when the IP address changes, when too many login attempts are detected, or when a browser appears unusual.
These settings are intended to protect the website, but they can also cause frequent logouts if they are too strict.
5. Changing IP address or network
WordPress itself does not always require a fixed IP address, but some security plugins or firewall rules may treat changing IP addresses as suspicious.
This can happen when switching between Wi-Fi and mobile data, using a VPN, or connecting through a network where the public IP changes often.
6. Plugin or theme conflicts
A plugin or theme can interfere with login sessions if it changes cookies, redirects, security headers, cache behavior, or user session handling.
This is more likely if the issue started after installing, updating, or changing a plugin or theme.
7. Incorrect SSL or HTTPS configuration
If SSL is active but WordPress is not configured consistently for HTTPS, login cookies may not be handled correctly.
This can happen when the website loads partly over HTTP and partly over HTTPS, or when redirects between HTTP and HTTPS are not consistent.
What to check first
Start with the simplest checks:
- Open WordPress in a private or incognito browser window.
- Try logging in again.
- Clear your browser cache and cookies for the website.
- Check whether the issue happens in another browser.
- Disable VPN temporarily if you are using one.
- Confirm that the website loads consistently with either
wwwor non-www. - Confirm that the website loads consistently over HTTPS.
- Review recent plugin, theme, or security changes.
- Clear any WordPress, server, or CDN cache.
- Check whether a security plugin has short session or forced logout rules.
WordPress Address vs. Site Address
WordPress login cookies depend on the website address being consistent.
In the WordPress admin area, these settings are usually found under:
Settings → General
The values should normally match the public version of the website.
For example:
WordPress Address: https://example.com
Site Address: https://example.com
If the website uses www, both should use www:
WordPress Address: https://www.example.com
Site Address: https://www.example.com
Avoid mixing http and https, or mixing www and non-www, unless your website has a specific configuration that requires it.
Cache and login pages
WordPress admin and login pages should not be cached.
The following paths should usually be excluded from cache:
/wp-admin/
/wp-login.php
For ecommerce, membership, or logged-in websites, additional pages may also need to be excluded from cache, such as account pages, checkout pages, or user dashboards.
If caching is the cause, clearing cache may help temporarily, but the better solution is to exclude login and admin areas from caching rules.
When the issue started matters
The timing of the issue can help identify the cause.
If WordPress started logging you out after a plugin update, theme change, SSL change, domain change, cache change, or security rule change, that recent change should be reviewed first.
If nothing changed on the website, check browser settings, VPN usage, network changes, and cookie behavior.
What is normal
It is normal for WordPress sessions to expire after some time. It is also normal to be asked to log in again after clearing browser cookies, changing browsers, or using a different device.
It is not normal to be logged out repeatedly every few seconds or every time you open a new admin page. That usually means cookies, cache, redirects, or security rules need to be reviewed.
When to contact support
Contact support if the issue continues after checking browser cookies, cache, address settings, HTTPS consistency, and recent plugin changes.
Include the following details:
- the website address
- when the issue started
- whether it happens in more than one browser
- whether it happens on another device or network
- whether you use a VPN
- whether any plugin, theme, SSL, or cache changes were made recently
- whether the issue happens immediately or after a period of inactivity
This information helps support identify whether the issue is related to the hosting environment, cache, SSL, redirects, or the WordPress application.
Summary
WordPress usually logs users out repeatedly when login cookies cannot be stored or matched correctly. The most common causes are mismatched website addresses, blocked cookies, cached login pages, strict security settings, plugin conflicts, or inconsistent HTTPS configuration.
Start by checking browser cookies, cache, WordPress address settings, SSL consistency, and recent changes. If the issue continues, support can review the environment with more context.