/** * Disable WordPress / WooCommerce Lost Password functionality. * * - Removes / redirects the "Lost your password?" URL. * - Blocks direct access to wp-login.php?action=lostpassword. * - Blocks wp-login.php?action=retrievepassword. * - Prevents WordPress password reset requests from being processed. * - Does NOT affect normal login. * - Does NOT affect 2FA during normal login. * - Administrators can still manually change passwords from WP Admin. */ /** * 1. Redirect all WordPress-generated Lost Password URLs * back to the normal login page. */ add_filter( 'lostpassword_url', function( $lostpassword_url, $redirect ) { return add_query_arg( 'password-reset', 'disabled', wp_login_url() ); }, 999, 2 ); /** * 2. Block direct access to native WordPress * Lost Password / Retrieve Password actions. */ add_action( 'login_init', function() { $action = isset( $_REQUEST['action'] ) ? sanitize_key( wp_unslash( $_REQUEST['action'] ) ) : 'login'; if ( in_array( $action, array( 'lostpassword', 'retrievepassword' ), true ) ) { wp_safe_redirect( add_query_arg( 'password-reset', 'disabled', wp_login_url() ) ); exit; } }); /** * 3. Server-side protection. * * Even if a plugin/theme tries to submit a native * WordPress password-reset request directly, * WordPress will reject it. */ add_action( 'lostpassword_post', function( $errors ) { if ( is_wp_error( $errors ) ) { $errors->add( 'password_reset_disabled', 'Password reset is currently disabled. Please contact the website administrator for assistance.' ); } }, 999 ); /** * 4. WooCommerce: * Redirect the My Account lost-password endpoint. */ add_action( 'template_redirect', function() { if ( function_exists( 'is_account_page' ) && is_account_page() && function_exists( 'is_wc_endpoint_url' ) && is_wc_endpoint_url( 'lost-password' ) ) { wp_safe_redirect( add_query_arg( 'password-reset', 'disabled', wc_get_page_permalink( 'myaccount' ) ) ); exit; } }); /** * 5. Display message on the WordPress login screen. */ add_filter( 'login_message', function( $message ) { if ( isset( $_GET['password-reset'] ) && 'disabled' === sanitize_key( wp_unslash( $_GET['password-reset'] ) ) ) { $message .= '