Hey @dekadinious,
Thanks for reporting this.
The fastest way back into your site would be to use ftp/sftp to access the web server, rename the wordfence folder in wp-content/plugins, then log in. Renaming a plugin folder immediately deactivates the plugin. Once you access the site you can rename the wordfence folder again and then activate the plugin, and then figure out what happened.
Can you please make sure your server/site and device times are in sync? The app-based TOTP method is time sensitive.
Can you also look for and share any errors you might see in the browser console?
https://www.wordfence.com/help/advanced/troubleshooting/#how-to-inspect-the-browser-console
Thanks,
Gerroald
Thank you for your suggestions.
I have been able to trace the problem to the plugin Google Analytics Dashboard for WP (GADWP) by ExactMetrics. With that plugin enabled, I get a “ga is not defined” error on the 2FA-page. That “blocks” the login button it seems. Hitting it twice makes it fire, but then it has fired twice which triggers an error. Deactivating the plugin makes the login work.
I will contact ExactMetrics to make them fix it.
Hey @dekadinious,
My apologies for the delayed response.
Thanks for sharing this! This is really helpful, and I’ve shared it with the team.
Please let us know if anything else comes up.
Thanks,
Gerroald