Plugin Support
wfphil
(@wfphil)
Hi @riseforward
When you said, “We have our wp-login.php page protected with apache htpasswd authentication. One of my admins has the credentials saved with his browser.”
If that is also blocking access to the wp-admin directory then we recommend that you remove the blocking rule as it will break WordPress AJAX functionality which Wordfence uses. Your theme and other plugins may use it too.
If the affected admin is using a password manager tool in the browser then either that or the browser is likely to be malfunctioning in some way and they will need to fix it.
The AJAX issue is understood. It was allowed via htaccess in wp-admin directory in the past.
This URL protection is done with Siteground’s “Protected URL” functionality which doesn’t seem to affect admin-ajax.
I was also locked out today. I disabled “Immediately lock out invalid usernames” which did the trick
Plugin Support
wfphil
(@wfphil)
Hi @riseforward
Thank you for the update.
@wfphil – FYI Brute Force Protection was still locking us all out – different browsers, some using password managers. Log shows the exceeded max login attempts with the same auth username, not a WP user. I disabled Brute Force Protection completely and it’s working now (we probably didn’t need it in the first place.)
Plugin Support
wfphil
(@wfphil)
Hi @riseforward
Thank you for the update.
When you said, “Log shows the exceeded max login attempts with the same auth username, not a WP user.”
Please provide a very precise and detailed description for which logs, “auth username”, “WP user”.