The forgot password link is not working on the Client Portal login page
If the forgot password link isn't working for you or your clients, this guide will help you diagnose and fix the most common issues. Work through each section based on the symptoms you're experiencing.
Issue 1: The reset email never arrives
This is the most common problem. Your client clicks "Lost your password?", submits their email, sees a confirmation message, but no email arrives.
Check spam folders first
Reset emails often get flagged as spam. Have your client check their spam, junk, and promotions folders for an email with the subject "[Your Site Name] Password Reset".
Test if WordPress is sending emails
Client Portal uses WordPress's built-in email system. If WordPress can't send emails, password resets won't work.
Go to WP Admin > Clients > Settings > Notifications
Select any notification type from the dropdown
Click "Send Test Notification"
Check if the test email arrives in your inbox
If the test email doesn't arrive, WordPress email is broken on your site. This affects all password resets, not just Client Portal.
Many hosting providers block PHP mail by default to prevent spam. This breaks WordPress email functionality.
Fix WordPress email delivery
Install an SMTP plugin to force WordPress to send emails through a reliable mail server:
Install WP Mail SMTP or Post SMTP plugin
Configure it with your email provider's SMTP settings (Gmail, SendGrid, Mailgun, etc.)
Send a test email through the plugin
Try the password reset again
If you're not sure how to set up SMTP, contact your hosting provider's support team. Most hosts offer SMTP services or can recommend settings.
Issue 2: The email arrives but has no reset link
Some users receive the password reset email, but it's missing the clickable link or shows a blank space where the link should be.
This was a bug in older versions of Client Portal that has been fixed. Update to the latest version to resolve this.
Update Client Portal
Go to WP Admin > Plugins
Find Client Portal in your plugin list
If an update is available, click Update Now
Test the password reset flow again
If you're already on the latest version and still see this issue, check your email client. Some older email programs don't render links properly. Ask your client to try viewing the email in a different email app or webmail interface.
Issue 3: Clicking the link does nothing or refreshes the page
Your client receives the email and clicks the reset link, but the page just refreshes or nothing happens.
Check if caching is interfering
Caching plugins and server-level caching often break login forms and password reset flows. The login page must be excluded from all caching.
Follow the complete caching exclusion instructions in Exclude Client Portal from cache. Pay special attention to excluding:
/client-portal-login/(your login page URL)Any URLs containing
?action=lostpasswordor?action=rpCookies starting with
wp-resetpass
WP Engine hosting in particular disables most cookies by default for caching performance. You'll need to specifically request cookie exclusions from their support team.
Flush your permalinks
WordPress permalink issues can prevent the password reset page from loading correctly.
Go to WP Admin > Settings > Permalinks
Don't change anything — just click Save Changes
Try the password reset link again
Check for JavaScript conflicts
Temporarily disable other plugins one by one to see if a conflict is preventing the reset form from working. Start with:
Security plugins that modify login behavior
Custom login page plugins
JavaScript minification or optimization plugins
Issue 4: The "Lost your password?" link is missing
If you don't see the "Lost your password?" link on your login page at all, the login form might not be set up correctly.
Add the login form to your page
Go to the page set as your Client Portal login page (usually
/client-portal-login/)Edit the page in your WordPress editor
Make sure the page contains either:
The
[client_portal_login]shortcode, ORThe "Login Form" Gutenberg block
Publish the page
The "Lost your password?" link appears automatically below the login form when it's properly inserted.
Issue 5: Reset link shows "invalid" or "expired" error
When your client clicks the reset link, they see a message like "Your password reset link appears to be invalid" or "Your password reset link has expired."
Password reset links expire after 24 hours
This is a WordPress security feature. If more than 24 hours have passed since requesting the reset, the link won't work. Your client needs to:
Go back to the login page
Click "Lost your password?" again
Request a new reset email
Use the new link within 24 hours
Caching can cause false "invalid" errors
If your client tries to use the link immediately and still gets an "invalid" error, this is usually a caching problem. See the caching section above and make sure cookies starting with wp-resetpass are excluded from your cache.
If you're using WP Engine or another managed host with aggressive caching, send them this message: "Our site uses Client Portal's forgot password function. It requires cookies named wp-resetpass-* to work on the login page at [your-site.com/client-portal-login/]. Can you exclude these cookies from caching?"
Still not working?
If you've tried all these solutions and password reset still isn't working:
Test the standard WordPress password reset at
yoursite.com/wp-login.php. If that doesn't work either, this is a WordPress or hosting configuration issue, not a Client Portal problem. Contact your hosting provider or a WordPress developer.Check your server error logs for PHP or mail errors. Your hosting control panel (cPanel, Plesk, etc.) usually has an error log viewer.
Contact Client Portal support with details about which solutions you tried and what error messages you're seeing.