Technical

WordPress 403 Forbidden Error: 7 Fixes That Actually Work (2026)

By Daniel Reyes•October 4, 2026•4 min read

Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.

Our top pick for most WordPress sites
Bluehost: free domain, free SSL, 24/7 support, 30-day money-back guarantee.
Check Bluehost Deal →

A 403 means the server understood you and said no. Not a crash, not a timeout - a refusal. Something is actively blocking the request: permissions, an .htaccess rule, a security plugin, a firewall, or an IP block. Five things cause nearly every WordPress 403, and the server error log tells you which one before you change a single file.

Before Touching Anything: Cheap Checks

  1. 1.Read the error log. cPanel > Metrics > Errors, or error_log in site root. "Permission denied" = permissions. "Client denied by server configuration" = .htaccess/mod_security. This single log line saves an hour of guessing.
  2. 2.Test incognito + another device + VPN off. A cached 403, a browser extension, or an IP block at your VPN's exit node can all fake the error. Loads elsewhere = IP-based block, not a site problem.
  3. 3.403 on a folder URL only? Like /uploads/. That is normal - directory listing is off and there's no index file. The server is protecting your file list. Visit a real page.

1. The wp-admin-Only Pattern: Security Rules First

403 on the whole site = permissions or .htaccess. 403 only on wp-admin/wp-login = a security rule, almost every time. Check in order:

  • -Security plugin blocklist: Wordfence/iThemes/Sucuri may have flagged your IP (failed logins, rate limits). Whitelist your IP from the plugin settings or via the plugin's mu-plugin removal.
  • -WAF/mod_security: your host's web application firewall flagged a request pattern. Check the log, ask support to whitelist the rule.
  • -Hotlink protection gone rogue: a CDN or cPanel hotlink rule can 403 legitimate requests - temporarily disable and test.

2. Fix File and Folder Permissions

The classic cause. WordPress needs: 755 on directories, 644 on files, 440 on wp-config.php. A plugin install, migration, or malware scan can silently flip them. Via FTP (FileZilla):

  1. 1.Right-click the site root > File Attributes > numeric 755 > "Recurse into subdirectories" > "Apply to directories only"
  2. 2.Again, numeric 644 > recurse > "Apply to files only"
  3. 3.wp-config.php individually > 440 (it's your database credentials - never world-readable)

Never chmod 777. It doesn't fix a 403 caused by wrong ownership - it just makes every file writable by every process on the server. If ownership is wrong, that's a chown for your hosting user, which shared hosts must run for you.

3. Regenerate .htaccess

Apache reads .htaccess on every request - one bad line 403s the whole site. Rename .htaccess to .htaccess_old via FTP and reload. Site back? A rule in the old file was the block (common: Require all denied, a stale IP deny list, hotlink rules). Regenerate clean via wp-admin > Settings > Permalinks > Save Changes. Nginx has no .htaccess - check location blocks in the site config instead.

4. Deactivate Plugins

Security, firewall, and some caching plugins can 403 on their own. Can't reach wp-admin? Rename wp-content/plugins to plugins_off via FTP. Site loads = a plugin did it. Rename back, reactivate one by one. Start suspicion with whatever plugin manages logins, firewalls, or IP rules.

5. Check the Index File

Every served directory needs an index file. If index.php was deleted, renamed, or an index.html is shadowing it, Apache may refuse the directory. Confirm index.php exists in site root with correct spelling and 644 permissions, and that DirectoryIndex index.php is set (default .htaccess handles this).

6. CDN and DNS

Cloudflare WAF rules can 403 specific countries, IPs, or request patterns - pause Cloudflare (or set Development Mode) and test. Wrong DNS records can point you at an old server where you have no permissions at all - verify the site resolves to the correct IP after any migration.

7. Malware Scan

Malware sometimes chmods files to lock them or injects deny rules into .htaccess. If the 403 came with other weirdness (new admin users, redirects for visitors only, pharma spam), scan before restoring permissions - otherwise you fix the symptom while the infection re-breaks it. Clean first, then permissions, then .htaccess.

Logs You Can Actually Read

Half of 403 diagnosis is reading one line of the error log - which some budget hosts hide. Bluehost exposes cPanel error logs with 24/7 support that can check server-level blocks you can't see. From $3.99/mo.

Get Reliable Hosting

Related: ERR_TOO_MANY_REDIRECTS fix - 500 internal server error - hacked site recovery - WordPress security hardening.

Find Your Perfect Hosting Plan

What are you building?

Tell us about your project so we can match the perfect hosting plan.

Question 1 of 425% complete
Interactive Tool

Hosting Cost Calculator

See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.

Used to calculate transaction fees (Shopify charges 2% on sales)

Shopify Basic (3yr)
$1,044
Bluehost (3yr)
$444
You Save
$600
58% less than Shopify Basic

Frequently Asked Questions

What does a 403 Forbidden error mean in WordPress?

The server received and understood your request but refuses to serve the page - you don't have permission. On WordPress the usual causes are wrong file/folder permissions, a corrupted .htaccess file, a security plugin or firewall blocking you, or a missing index file.

What file permissions should WordPress use?

Directories: 755 (or 750). Files: 644 (or 640). wp-config.php: 400 or 440 - it contains database credentials and must never be world-readable. Never use 777; it fixes nothing and makes every file writable by any process on the server.

Why do I get 403 only on wp-admin or wp-login?

That pattern almost always means a security rule, not permissions: a security plugin (Wordfence, iThemes), a WAF/mod_security rule, or an IP block. Check the security plugin's block list and your host's firewall before touching file permissions.

How do I fix a 403 caused by .htaccess?

Via FTP, rename .htaccess to .htaccess_old and reload. If the site works, a rule in the old file (like 'Require all denied' or a bad IP block) caused it. Regenerate via wp-admin > Settings > Permalinks > Save Changes.

Can a CDN or VPN cause a 403?

Yes. Cloudflare WAF rules can 403 requests from flagged IPs or regions, and many sites block known VPN exit-node IPs. Test in incognito, from another network, and with the VPN off. If it loads elsewhere, the block is IP-based, not site-based.

How do I find what actually caused the 403?

Read the server error log (in cPanel or /var/log/apache2/error_log). A 'Permission denied' line points to file permissions; 'client denied by server configuration' points to .htaccess or mod_security. The status code never tells you - the log line does.

Ready to launch?

Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.

Start for $3.99 →

Related Articles