Members and the site's own administrators were locked out of login. Two-factor codes never arrived, and the login form showed multiple, conflicting reCAPTCHA boxes.
Members could not log in with the right password, and the admins were locked out too.
Cause
A combination of conflicting security plugins, missing SMTP, and restrictive hosting-level settings.
Fix
Restored admin access, disabled the login limiter, configured SMTP, and removed the duplicate security layers.
Result
Admins and members back in. Active plugins cut from 27 to 19, a 30 percent reduction, with no functionality lost.
How we traced it and fixed it
Root cause in detail
The host had installed a login-limiting plugin as a must-use plugin, which cannot be disabled from the WordPress dashboard, and its own two-factor and reCAPTCHA clashed with WordPress login. A second security plugin added a duplicate layer of two-factor. No SMTP was configured, so two-factor codes were not reliably delivered. Host-level page caching could not be excluded from membership pages.
The fix in detail
Regained admin access first, by enabling a two-factor grace period directly in the database. Disabled the login limiter at the file-system level, via the must-use plugins folder. Configured SMTP so two-factor codes and password resets deliver. Removed the duplicate security layers and streamlined the two-factor and reCAPTCHA setup.
How findings are ranked
- Critical
Members or admins locked out, or members paying but locked out of content they paid for.
- High
A failure caught before it hits members, like the 4th simultaneous login failing under load testing.
- Medium
A slow build-up, like 27 or more active plugins, several unused or duplicating each other.
Source: Fixing Broken Membership Logins and Locked-Out Members