What the WordPress cookies blocked error means
WordPress uses cookies during login to identify the browser session and confirm that cookies can be stored. If that test fails, the login screen may show Error: Cookies are blocked or not supported by your browser.
The wording can be misleading. Cookies may genuinely be disabled, but the browser can also reject a cookie because WordPress is trying to set it for the wrong hostname, the HTTP and HTTPS configuration does not agree, or another component interferes with the login response.
If the error started immediately after a domain change, migration, HTTPS change, caching change or security plugin update, treat that recent change as useful diagnostic evidence rather than repeatedly resetting the password.
Common causes of cookies being blocked in WordPress
Start by separating a browser problem from a WordPress problem. If the login works in another current browser or a private window, clear the cookies and cached site data for the affected domain and confirm that cookies are allowed.
When the error appears across several browsers or devices, common site-side causes include:
- WordPress Address and Site Address do not agree. Differences such as www versus non-www, HTTP versus HTTPS, or an old migration domain can prevent the login cookie being returned correctly.
- A security or login plugin is interfering. Cookie hardening, login protection, redirects and custom authentication rules can break the normal WordPress login flow after an update or configuration change.
- HTTPS is being detected incorrectly. This can happen after moving behind a reverse proxy, CDN or load balancer if WordPress receives inconsistent information about whether the original request was secure.
- Cached login responses or redirects are being served. WordPress login and administration URLs should not normally be handled like public cacheable pages.
- PHP output is being sent before WordPress sets its cookies. A warning, stray output or badly edited PHP file can interfere with HTTP headers and may be accompanied by a headers already sent warning.
How to fix the WordPress cookies blocked error safely
Before editing files or the database, take a full backup of both the site files and database.
- Try a private browser window, then clear cookies and cached data for the website. Check that the browser is not blocking cookies for the domain.
- Open the site using the exact public address you expect WordPress to use. Avoid switching between HTTP and HTTPS or between www and non-www while testing.
- If you can reach the dashboard through another administrator account, check Settings > General and confirm that the WordPress Address and Site Address are correct. Also review any recent security, redirect or caching changes.
- If the error began after a security plugin change and you cannot reach wp-admin, use your host's file manager or SFTP to rename that specific plugin directory inside wp-content/plugins. Test login again, then restore the folder name before deciding whether the plugin needs reconfiguration, updating or replacement.
- Check wp-config.php for manually defined WP_HOME or WP_SITEURL values. They should match the intended scheme and hostname. Do not add these constants simply as a guess.
- If login access is the immediate problem, use WordPress's normal password reset email first. If another administrator account already exists, it can reset the affected user's password from the dashboard.
- If email recovery is unavailable and you have shell access, WP-CLI is preferable to directly editing password data. For example, identify the correct user first and use an interactive prompt rather than placing the new password in shell history:
wp user update 123 --prompt=user_pass - As a database fallback, WordPress documentation permits replacing the affected user_pass value in the correct users table through phpMyAdmin using MD5 for a new temporary password. Confirm the database and user record carefully, then log in and immediately set a new strong password through the WordPress profile screen. Direct database editing carries more risk than WP-CLI.
Never send a WordPress, hosting, database or SFTP password by ordinary email or include it in a support ticket.
When to stop troubleshooting the WordPress login error
Stop making changes if the error follows a migration and you are unsure which database or installation is live, if changing a plugin causes a different fatal error, or if the site has inconsistent redirects that could involve the web server, proxy or CDN. Repeatedly changing URLs in the database can make recovery harder.
You should also investigate further if the login problem appears alongside unexpected administrator accounts, malicious redirects, changed files or other signs of compromise. A cookie error by itself does not prove the site has been hacked.
Web Support Services offers an Emergency Fix for £249 per incident with a response within 2 working hours. For ongoing maintenance, monitoring and updates, care plans start from £59 a month.