• Pricing
  • Help
  • My Account
  • Download
WP Ghost
  • Pricing
  • Help
  • My Account
  • Download

Getting Locked Out After Exceeding Max Fail Attempts

/Troubleshooting /Getting Locked Out After Exceeding Max Fail Attempts

By default, if you fail to enter the correct credentials or the 2FA code five times, your IP will be blocked for a period of time.

During the lockout you will get a message like:

Your IP has been flagged for potential security violations. Please try again in a little while.

Solutions:

Solution 1: Wait for the ban duration to expire (default is 15 minutes).

Solution 2: Access the login page using the Safe URL from your WP Ghost Dashboard (Cloud Account). This will deactivate WP Ghost until you log in to the WordPress dashboard with your credentials.

Access login with Safe URL

Solution 3: If you have admin access via File Manager or FTP, disable the WP Ghost plugin by changing the plugin directory hide-my-wp to hide-my-wp1.

rename hide-my-wp directory

After logging in, change the hide-my-wp directory back to re-enable the WP Ghost plugin on your website and clear the blocked IP address from WP Ghost > Brute Force.

Tagged: error2fa fail atteptsblocked ipyour IP has been flaggedsafe login

Related Articles

  • Cache Plugins Not Minifying CSS and JS Files

  • The New Admin Path Is Redirected To Front Page When Logged In

  • The New Admin Path Is Redirected To Front Page

  • Elementor Stopped Working After Changing Paths

  • The Paths Are Not Changed in Frontend After Activating this Option

  • Temporary Login URL is Redirecting to the Home Page

WP Ghost - Best Practice

Learn how to set up WP Ghost in Ghost Mode and activate all the security features you need for a stronger and safer website.

Most Popular

  • Change and Hide wp-admin Path with WP Ghost
  • WP Ghost Compatibility Plugins List
  • Setup WP Ghost on Nginx Server
  • Set AllowOverride all on Apache Servers
  • Theme Not Loading Correctly and Website Loads Slower
  • Lesson 3 – Hide Your Site From Theme Detectors and Hackers Bots
  • Lesson 1 – Customize Paths with WP Ghost
  • Change admin-ajax.php Path with WP Ghost
  • Firewall and Security
  • How To Change File Permissions in WordPress
  • Change plugins Path with WP Ghost
  • Brute Force Attack Protection
  • WP Ghost Settings – Best Practice
  • Change REST API Path with WP Ghost
  • Change and Hide wp-login Path with WP Ghost
  • Redirects
  • Change wp-content Path with WP Ghost
  • What is WP Ghost?
  • Two-Factor Authentication
  • Brute Force Protection in Elementor Login Forms
  • Change wp-register Path with WP Ghost
  • Disable Right-Click and Keys
  • Hide wp-admin And wp-login.php From Source Code
  • WP Ghost Compatibility Themes List
  • Website Security Check
  • Install WP Ghost Lite Plugin
  • Change author Path and Hide ID with WP Ghost
  • Temporary Logins
  • Setup WP Ghost on Nginx Web Server With Virtual Private Server
  • Change Paths In Cached Files

Recommended

  • What is WP Ghost?
  • Changelog
  • Plugin Best Practice
  • Plugin Compatibility
  • Theme Compatibility

Categories

  • Change Paths
  • Firewall
  • Temporary Login
  • Two Factor
  • Brute Force
  • Events Log

Company

  • Affiliate
  • Media Kit
  • Terms Of Use
  • Privacy Policy
  • Contact

Useful

  • Hack Attack Types
  • Key Security Features
  • Security Features
  • Free vs PRO
  • Why WP Ghost
  • Pricing
  • Facebook
  • YouTube
  • X
© WP Ghost 2016-2025