WordPress 403 Forbidden Error: 7 Fixes That Actually Work (2026)
Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.
A 403 means the server understood you and said no. Not a crash, not a timeout - a refusal. Something is actively blocking the request: permissions, an .htaccess rule, a security plugin, a firewall, or an IP block. Five things cause nearly every WordPress 403, and the server error log tells you which one before you change a single file.
Before Touching Anything: Cheap Checks
- 1.Read the error log. cPanel > Metrics > Errors, or
error_login site root. "Permission denied" = permissions. "Client denied by server configuration" = .htaccess/mod_security. This single log line saves an hour of guessing. - 2.Test incognito + another device + VPN off. A cached 403, a browser extension, or an IP block at your VPN's exit node can all fake the error. Loads elsewhere = IP-based block, not a site problem.
- 3.403 on a folder URL only? Like
/uploads/. That is normal - directory listing is off and there's no index file. The server is protecting your file list. Visit a real page.
1. The wp-admin-Only Pattern: Security Rules First
403 on the whole site = permissions or .htaccess. 403 only on wp-admin/wp-login = a security rule, almost every time. Check in order:
- -Security plugin blocklist: Wordfence/iThemes/Sucuri may have flagged your IP (failed logins, rate limits). Whitelist your IP from the plugin settings or via the plugin's mu-plugin removal.
- -WAF/mod_security: your host's web application firewall flagged a request pattern. Check the log, ask support to whitelist the rule.
- -Hotlink protection gone rogue: a CDN or cPanel hotlink rule can 403 legitimate requests - temporarily disable and test.
2. Fix File and Folder Permissions
The classic cause. WordPress needs: 755 on directories, 644 on files, 440 on wp-config.php. A plugin install, migration, or malware scan can silently flip them. Via FTP (FileZilla):
- 1.Right-click the site root > File Attributes > numeric
755> "Recurse into subdirectories" > "Apply to directories only" - 2.Again, numeric
644> recurse > "Apply to files only" - 3.wp-config.php individually >
440(it's your database credentials - never world-readable)
Never chmod 777. It doesn't fix a 403 caused by wrong ownership - it just makes every file writable by every process on the server. If ownership is wrong, that's a chown for your hosting user, which shared hosts must run for you.
3. Regenerate .htaccess
Apache reads .htaccess on every request - one bad line 403s the whole site. Rename .htaccess to .htaccess_old via FTP and reload. Site back? A rule in the old file was the block (common: Require all denied, a stale IP deny list, hotlink rules). Regenerate clean via wp-admin > Settings > Permalinks > Save Changes. Nginx has no .htaccess - check location blocks in the site config instead.
4. Deactivate Plugins
Security, firewall, and some caching plugins can 403 on their own. Can't reach wp-admin? Rename wp-content/plugins to plugins_off via FTP. Site loads = a plugin did it. Rename back, reactivate one by one. Start suspicion with whatever plugin manages logins, firewalls, or IP rules.
5. Check the Index File
Every served directory needs an index file. If index.php was deleted, renamed, or an index.html is shadowing it, Apache may refuse the directory. Confirm index.php exists in site root with correct spelling and 644 permissions, and that DirectoryIndex index.php is set (default .htaccess handles this).
6. CDN and DNS
Cloudflare WAF rules can 403 specific countries, IPs, or request patterns - pause Cloudflare (or set Development Mode) and test. Wrong DNS records can point you at an old server where you have no permissions at all - verify the site resolves to the correct IP after any migration.
7. Malware Scan
Malware sometimes chmods files to lock them or injects deny rules into .htaccess. If the 403 came with other weirdness (new admin users, redirects for visitors only, pharma spam), scan before restoring permissions - otherwise you fix the symptom while the infection re-breaks it. Clean first, then permissions, then .htaccess.
Logs You Can Actually Read
Half of 403 diagnosis is reading one line of the error log - which some budget hosts hide. Bluehost exposes cPanel error logs with 24/7 support that can check server-level blocks you can't see. From $3.99/mo.
Get Reliable HostingRelated: ERR_TOO_MANY_REDIRECTS fix - 500 internal server error - hacked site recovery - WordPress security hardening.
What are you building?
Tell us about your project so we can match the perfect hosting plan.
Hosting Cost Calculator
See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.
Used to calculate transaction fees (Shopify charges 2% on sales)
Frequently Asked Questions
What does a 403 Forbidden error mean in WordPress?
The server received and understood your request but refuses to serve the page - you don't have permission. On WordPress the usual causes are wrong file/folder permissions, a corrupted .htaccess file, a security plugin or firewall blocking you, or a missing index file.
What file permissions should WordPress use?
Directories: 755 (or 750). Files: 644 (or 640). wp-config.php: 400 or 440 - it contains database credentials and must never be world-readable. Never use 777; it fixes nothing and makes every file writable by any process on the server.
Why do I get 403 only on wp-admin or wp-login?
That pattern almost always means a security rule, not permissions: a security plugin (Wordfence, iThemes), a WAF/mod_security rule, or an IP block. Check the security plugin's block list and your host's firewall before touching file permissions.
How do I fix a 403 caused by .htaccess?
Via FTP, rename .htaccess to .htaccess_old and reload. If the site works, a rule in the old file (like 'Require all denied' or a bad IP block) caused it. Regenerate via wp-admin > Settings > Permalinks > Save Changes.
Can a CDN or VPN cause a 403?
Yes. Cloudflare WAF rules can 403 requests from flagged IPs or regions, and many sites block known VPN exit-node IPs. Test in incognito, from another network, and with the VPN off. If it loads elsewhere, the block is IP-based, not site-based.
How do I find what actually caused the 403?
Read the server error log (in cPanel or /var/log/apache2/error_log). A 'Permission denied' line points to file permissions; 'client denied by server configuration' points to .htaccess or mod_security. The status code never tells you - the log line does.
Ready to launch?
Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.
Related Articles
Bluehost vs Competitors: The Technical Deep Dive
We ran 47 benchmarks over 90 days. Here's the raw data on why Bluehost dominates.
Fix ERR_TOO_MANY_REDIRECTS in WordPress (2026): The 6 Real Causes
ERR_TOO_MANY_REDIRECTS means an infinite redirect loop. Match your Site URLs, fix Cloudflare SSL mode, reset .htaccess, kill plugin conflicts - step-by-step with code.
Fix 502 Bad Gateway in WordPress (2026): Diagnose First, Then Fix
502 means the gateway got a bad response from your server - usually PHP timeouts, CDN issues, or overload. A 9-step diagnostic workflow from browser checks to server logs.
Fatal Error: Maximum Execution Time Exceeded - 6 Fixes (2026)
max_execution_time kills slow updates at 30-60s. Fix the culprit plugin/theme first, then raise the limit via wp-config, .htaccess or php.ini - with exact code.
HTTP Error Uploading Images in WordPress: 9 Fixes Ranked (2026)
The vague 'HTTP error' on image upload usually means memory limits or Imagick. Fix order: rename the file, bump memory, force GD library, check permissions - with code.
WordPress Missed Schedule Error: Why Posts Don't Publish (2026)
Missed Schedule means wp-cron didn't fire - it's triggered by visits, not real time. Fix with a real server cron, a trigger plugin, or the underlying cache/timezone issue.