How to fix the 403 Forbidden error in WordPress
A 403 means the server understood the request and refused it. On a WordPress site the refusal comes from a rule in .htaccess, a security plugin, file permissions or the host's firewall. Who is refused, and on which pages, tells you which one to look at.
- By
- WP Ministry
- Published
- Tested on
- WordPress 7.1.3, PHP 8.3.35
In short
- A 403 is a refusal, not damage. Your content has not been touched.
- If the site loads for other people and not for you, your address has been blocked by a security plugin or by the host.
- If everyone is refused on every page, look at .htaccess first, then at file permissions.
- Never set files or folders to 777 to get past a 403.
"403 Forbidden" is the server saying that it understood the request and will not answer it. Logging in again makes no difference. A 404 means the page could not be found. A 403 means something decided you may not have it: a rule in a file, a plugin, a permission or a firewall.
Your posts, pages and settings are not affected.
Find out who is refusing you
- Does the site load on another connection? Try your phone on mobile data. If it loads there, your own address is blocked: start with the security plugin, then ask the host.
- Does it only happen when you save, upload or send a form? The host's firewall is refusing that one request. Go to the last fix.
- Is everyone refused, on every page? Look at
.htaccess, then at permissions.
The page itself is a clue. A plain page that says "Forbidden" and "You don't have permission to access this resource." comes from the web server. A page that carries a product's name comes from that plugin or service.
Where it goes wrong
A page request passes through each of these in turn. This one comes from the web server.
- Browser
- DNS
- HTTPS
- CDN or firewall
- Web server (this error comes from here)
- PHP
- WordPress
- Database and files
What causes it
A rule in .htaccess turns visitors away
CommonA line added by a plugin or by hand tells the web server to refuse everyone, or to let in a single address that is no longer yours.
A security plugin has blocked you
CommonSecurity plugins lock out an address after failed logins, and can block by country or by rule. The page they show usually carries the plugin's name.
The web server cannot read a file or open a folder
SometimesAfter a move, a restore or a bulk change, files and folders can carry permissions that shut the web server out. It refuses to serve what it cannot read.
The host's firewall is refusing the request
SometimesThe hosting company's firewall has blocked your address, or one of its rules has mistaken an ordinary request, such as saving a post, for an attack.
How to fix it
Replace .htaccess with WordPress's standard one
- Easy
- Back up first
- About 5 minutes
- Steps tested on WordPress 7.1.3
This applies to sites on Apache or LiteSpeed. nginx has no .htaccess file.
Step 1: Download a copy of .htaccess
It sits in the site's main folder, beside
wp-config.php. Its name begins with a dot, so turn on "Show hidden files" in your file manager if you cannot see it.Step 2: Look for a line that refuses
Deny from all,Require all denied, orRequire ipfollowed by an address all tell the server to turn visitors away. The last one lets in only the address it names.Step 3: Replace everything in the file with this
This is what WordPress itself writes for a site at the root of its domain.
.htaccess# BEGIN WordPress <IfModule mod_rewrite.c> RewriteEngine On RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> # END WordPressStep 4: Reload the site
If it loads, a line in the old file was refusing you. Put your other rules back one section at a time from the copy, and leave out the one that brings the 403 back.
If WordPress is installed in a subfolder, such as example.com/blog, do not paste the block above. Rename .htaccess to .htaccess-old, then go to Settings, then Permalinks in the dashboard and press Save Changes. WordPress writes a fresh file with the right paths.
To undo it: Put your copy of the old .htaccess back.
Switch off the security plugin that blocked you
- Takes care
- Low risk
- About 10 minutes
- Steps tested on WordPress 7.1.3
Step 1: Rename the plugin's folder
In your host's file manager or over SFTP, open
wp-content/plugins/and add-offto the name of the security plugin's folder. WordPress can no longer find the plugin, so it stops running.Step 2: Reload the site and log in
If the site loads, that plugin was refusing you. Open the Plugins screen once, so that WordPress records the plugin as switched off.
Step 3: Put the plugin back and clear the block
Rename the folder back and activate the plugin. Go straight to its settings and take your address off its block list, or add it to the list of addresses it always allows.
With WP-CLI, use the plugin's folder name:
wp plugin deactivate plugin-folder-nameSwitching the plugin off keeps its settings, its block list included, so it may lock you out again when it is back on. If it does, switch it off the same way and ask the plugin's support how to clear the block.
To undo it: Rename the folder back, or activate the plugin again.
Set folders to 755 and files to 644
- Takes care
- Low risk
- About 15 minutes
- Steps tested on WordPress 7.1.3
The web server has to be able to open every folder and read every file. WordPress's own guidance is 755 for folders and 644 for files.
Step 1: Check the main folder first
In your file manager or SFTP program, look at the permissions of the site's main folder, of
wp-admin,wp-contentandwp-includes, and of.htaccessandindex.php. A folder that is not 755, or a file that is not 644, is a likely cause.Step 2: Set folders to 755 and files to 644
Most file managers and SFTP programs can apply a permission to everything inside a folder, to folders only or to files only. Do the folders first, then the files, then reload the site.
Over SSH, run these two commands from the site's main folder. The first sets every folder, the second every file.
find . -type d -exec chmod 755 {} \;
find . -type f -exec chmod 644 {} \;If your host told you to keep wp-config.php tighter than 644, set that again afterwards.
Do not set anything to 777. It lets every account on the server change your files.
If the numbers were already right, the files may belong to the wrong user on the server. Only the host can change that.
Ask the host to check its firewall
- Easy
- No risk
- About 15 minutes
Many hosts run a web application firewall, often ModSecurity, in front of every site. It blocks addresses that look hostile and requests that look like attacks. A post that contains code can trip a rule by mistake.
Step 1: Write down what happened
Note the address of the page, the time, what you were doing and your own IP address. Searching the web for "what is my IP" shows it.
Step 2: Send that to the host's support
Ask whether your IP address is blocked, and whether a firewall rule refused the request at that time. They can see the rule in their log and can lift the block or switch that rule off for your site.
When to get help
If .htaccess is the standard one, folders are 755 and files 644, your security plugin is switched off and the 403 is still there, the refusal comes from the host's firewall or the server's own configuration. Only the host, or someone with access to the server, can see which rule it is.
Common questions
A folder address such as /wp-content/uploads/ shows 403. Is something wrong?
No. When a folder has no index file and the server is set not to list what is in it, a 403 is the correct answer. The files inside still load by their own addresses.
Why am I the only one who sees the 403?
Your address has been blocked, by a security plugin after failed logins or by the host's firewall. Check from another connection to confirm it, then use the second and fourth fixes.
Only the login page shows 403. Why?
Some .htaccess rules refuse only one file, such as wp-login.php, to every address but one. If your own address has changed since the rule was written, it now refuses you. The first fix removes it. If the login page loads but will not let you in, see the login page that keeps reloading.
- GuideLocked out of WordPress admin: find which lockout you have and get back in
- GuideSlow WordPress admin: how to find the cause and fix it
- ResourceWooCommerce checkout is down: a runbook
- GuideWordPress site not showing up on Google: what to check, in order
- Guideadmin-ajax.php high CPU usage in WordPress: how to find what is calling it
- GuideHow to change WordPress permalinks without breaking your old links

