"The Link You Followed Has Expired" in WordPress
WordPress shows a bare page saying "The link you followed has expired. Please try again." — usually when installing a theme or plugin that is too big for the server, sometimes because a form or login session went stale.
Common signs of this issue
- A plain white page says "The link you followed has expired. Please try again." with a link back to the previous screen.
- It happens when you upload a theme or plugin zip under Appearance, then Themes, then Add New, or Plugins, then Add New, then Upload Plugin.
- Premium themes and page-builder packages fail, while small free plugins install normally.
- It can also appear when you save a post, change settings, or submit a form after the page has been open for hours.
- Sometimes it only happens after a site move, a domain change, or switching between http and https.
- Retrying the exact same upload gives the exact same message.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Note what you were doing. If you were uploading a theme, plugin, or import file, this is almost certainly a size limit. If you were saving a page or settings after leaving the tab open a long time, it is probably an expired security token.
- For uploads, check the size of the zip file on your computer, then go to Media, then Add New and read the "Maximum upload file size" line. If the zip is larger than that figure, you have found the cause.
- Check whether the zip you downloaded is the right file. Many premium theme sellers give a large "everything" package containing documentation and demo content, with the actual installable theme zip inside it. Unzip it on your computer and look for the smaller theme or plugin zip.
- To raise the limits, open your host's PHP settings — in cPanel this is usually the MultiPHP INI Editor — and increase
upload_max_filesize,post_max_size(same or slightly larger), andmax_execution_time. Save, then try again. The full walkthrough is in upload_max_filesize exceeded. - If your dashboard has no PHP settings, ask your host's support to raise the upload size, post size, and execution time for your site. It is a routine request.
- As an alternative for a large plugin or theme, many developers let you install directly from the WordPress directory (Plugins, then Add New, then search) or upload the unzipped folder by SFTP or the host's File Manager instead of through the browser. Only do the latter if you are comfortable with files on the server.
- For the stale-session version, copy any unsaved text somewhere safe first, reload the page, and try again. If that fails, log out, log back in, and repeat the action.
- If it keeps happening on normal saves, clear your browser's cookies for your site and check that the WordPress Address and Site Address under Settings, then General both use the same domain and https. A mismatch after a move can cause login and session problems.
What this usually means
This message is WordPress's generic answer when a request arrives without the security token it expected. WordPress adds a hidden one-time code, called a nonce, to forms and upload screens so it can tell a genuine request from a forged one. If that code is missing or too old, WordPress refuses the request and shows this page. The wording is misleading — nothing was really a "link" — which is why people find it so confusing.
The most common way the token goes missing is an upload that is bigger than the server's post_max_size. When that happens, PHP throws away the entire submission, file and hidden fields alike, so WordPress sees a request with no token and assumes it expired. That is why it strikes theme and plugin uploads so often: premium themes and bundled page builders can be tens of megabytes, and many hosts ship with small defaults. Raising the PHP limits, or uploading the correct smaller zip, is the fix. Slow uploads that exceed the server's time limit can cause the same result.
The less common cause is genuine expiry. Tokens last for a limited time — typically up to a day — and a page left open overnight, a login that timed out, or cookies that were cleared can all make the next save fail. Occasionally a caching plugin or host cache serves an old copy of an admin or form page with a stale token baked in. If login itself keeps failing, see WordPress admin login not working. If the error began right after a plugin update, plugin update broke the site may be the better starting point, and an outdated PHP version on the server is worth ruling out via PHP version compatibility problems.
What not to do
- Don't keep retrying the same large upload. If the file is over the limit, it will fail the same way every time.
- Don't copy random code into .htaccess or functions.php to raise limits. One wrong line in .htaccess can take the whole site down.
- Don't upload the full download package from a theme seller when it contains a smaller installable zip inside.
- Don't install nulled or pirated premium themes and plugins to get around a purchase. They are a common source of hidden malware.
- Don't lose your work: copy any long text out of the editor before reloading a page that shows this error.
- Don't disable security plugins or caching just to make the message go away without knowing which one caused it.
When to get help
If you have raised the PHP limits and the upload still fails, if the message appears on ordinary saves across the site, or if it started after a site move or domain change, the cause is harder to see from the dashboard: a web server limit your host controls, a caching layer serving stale admin pages, mismatched site URLs, or cookies being set on the wrong domain. Each of those takes a few minutes to confirm from the server side and a lot longer to guess at, and repeated trial-and-error edits on a live site are how small problems become outages. It is also worth getting help if the theme you are installing is replacing an existing one on a site that brings in business — a theme switch deserves a staging copy and a backup first.
Glenn, who runs WebsiteSelfHelp, clears up WordPress errors like this one for small businesses. Describe what you were doing when the message appeared and he will tell you whether it is a size limit, a session problem, or something deeper, and what it will take to fix. You can start without sharing any logins.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does "The link you followed has expired" mean in WordPress?
WordPress received a request without a valid security token. Most often that is because an upload was too large and the server discarded it, and sometimes because the page or login session was simply too old.
Why do I get "The link you followed has expired" when uploading a theme?
The theme zip is bigger than your server's upload or post size limit, so the upload is thrown away before WordPress can check it. Raise the PHP limits, or make sure you are uploading the installable theme zip rather than the full download package.
How do I fix "The link you followed has expired"?
For uploads, increase upload_max_filesize, post_max_size, and max_execution_time in your host's PHP settings or ask support to do it. For saves and forms, reload the page, log in again, and retry.
Is "The link you followed has expired" a sign my site was hacked?
Almost never. It is a normal security check failing, usually because of an upload limit or an old session. It is worth investigating only if it appears together with unfamiliar users, redirects, or other strange behaviour.
What size should the WordPress upload limit be for themes?
Most theme and plugin zips fit comfortably within 64 MB. Some bundled premium packages are larger, so check the zip size and set the limit a little above it.
Can I fix this myself without a developer?
Usually. Changing PHP settings in your hosting dashboard or asking your host to raise them solves most cases. If limits are raised and it still fails, a server-level setting or caching problem likely needs a professional look.