What the WordPress expired link message means
WordPress uses time-limited security tokens, called nonces, for many administrative actions. They help WordPress check that a request came from an expected screen and user session. If a token is no longer valid, WordPress can stop the action and show the expired-link message.
The same wording is often encountered while uploading a plugin or theme ZIP. In that situation, PHP upload limits or request limits can be relevant because a request that exceeds the server configuration may not reach WordPress in the form it expects.
The context therefore matters. If the error appears after leaving an admin screen open for a long time, refresh the screen and retry the action. If it consistently occurs with one large upload, check the server's PHP limits rather than repeatedly uploading the same file.
Common causes of the link expired error
An expired login session or WordPress nonce is the simplest cause. Signing in again or reloading the original admin screen generates a fresh request.
For theme and plugin uploads, PHP settings such as upload_max_filesize and post_max_size control how much data a request can contain. The PHP manual specifies that post_max_size must be larger than upload_max_filesize. Hosting platforms may also impose their own limits that override or cap local PHP settings.
Security plugins, hosting firewalls or request filtering can occasionally reject an administrative request in a way that produces similar symptoms. If the message began immediately after a security or hosting change, check logs before increasing unrelated resource values.
How to fix the WordPress expired link error safely
Take a full backup of both the website files and database before editing files or server configuration.
- Refresh the original admin page and sign in again if required. This is the correct first step when the screen has been open for a long time or the session may have expired.
- Confirm the upload size. If the error occurs while installing a plugin or theme, compare the ZIP file size with the upload limits shown by your hosting control panel or WordPress Site Health information.
- Check PHP upload settings. The relevant PHP directives normally include upload_max_filesize and post_max_size. Your host may provide a PHP settings screen. On servers where you manage php.ini, a configuration might look like this:
upload_max_filesize = 64M
post_max_size = 80MThose values are examples, not universal recommendations. Use limits appropriate to the file you actually need to upload and the resources available on the server. PHP requires post_max_size to exceed upload_max_filesize.
- Confirm which configuration is active. Do not assume a local php.ini overrides host-level PHP-FPM or control-panel settings.
- Retry with a fresh WordPress screen. If the file is within the active limits but the request still fails, inspect server and security logs before changing more settings.
Do not edit WordPress core files to increase upload limits, and never delete wp-config.php as part of troubleshooting.
When to get help with expired link errors
Get technical help if small uploads work but valid larger files consistently fail despite suitable active PHP limits, or if the error affects ordinary administrative actions rather than uploads. That can indicate a session, security, proxy or server configuration issue rather than a simple size restriction.
Stop before changing hosting-wide PHP settings if several sites share the same server configuration. A larger upload limit changes what the server will accept and should be set deliberately rather than copied from an arbitrary tutorial.
Web Support Services offers an Emergency Fix for £249 per incident, with a response within 2 working hours. Care plans start from £59 a month for ongoing WordPress maintenance designed to reduce repeat technical failures.