Resolving the WordPress 403 forbidden error
Common causes of the 403 forbidden error in WordPress and how to fix them, including file permissions, .htaccess corruption, security plugin lockouts and server-level blocks.
A 403 forbidden error means the server understood your request but is refusing to allow it.1 Instead of the page, you see an "access denied" or "forbidden" message. It can affect a single page, your whole site or just the WordPress admin area.
In WordPress, a 403 is usually caused by one of a handful of things: wrong file permissions, a faulty .htaccess file, a security plugin blocking your IP address or a server firewall rule. The fix depends on which one is responsible, so it's worth working through them in order.
Start with the basics
Before changing anything, rule out the simple things.
Refresh the page, clear your browser's cache and cookies for the site, or try a private or incognito window. Old cookies or cached responses can occasionally cause a 403 that isn't really there.
Also check the address you're visiting. If it's a folder that doesn't contain an index.php or index.html file, many servers return a 403 on purpose rather than listing the folder's contents. That's normal server behaviour rather than a WordPress problem.
Reset .htaccess
On Apache and LiteSpeed servers, the .htaccess file in your WordPress root folder controls how the server handles addresses, redirects and access rules. If it's damaged or contains overly strict rules (often left behind by plugins), it can cause a 403 on part or all of your site.
Connect via SFTP or your hosting file manager and rename .htaccess to .htaccess_old. Renaming rather than deleting keeps a copy of any custom rules you might need later. Then try loading your site. If the 403 has gone, the file was the problem.
To create a clean .htaccess, log into your dashboard, go to Settings → Permalinks and click Save Changes without changing anything. WordPress writes a new file with its default rules. If the old file contained rules you still need, copy them back from .htaccess_old one block at a time, checking the site after each, so you can spot the one causing the 403.
If you can't reach the dashboard, you can create the file by hand with WordPress's default rules.2 Our permalink troubleshooting guide has a copy of them, including what to change if WordPress is in a subfolder.
If your server runs Nginx, there's no .htaccess file. Nginx has its own configuration, which your hosting provider will need to check.
Check file and folder permissions
WordPress's guidance is that folders should normally be 755 (or 750) and files 644 (or 640). It recommends stricter permissions for wp-config.php, such as 440 or 400, on some server setups.3
If permissions have been changed (by a plugin, a migration tool or someone editing files), the server may refuse to serve files and return a 403.
You can check permissions in your hosting file manager or an SFTP client. Recursive permission changes are easy to apply too broadly, and some files may have been set more strictly on purpose by your host, so take a backup first and ask your host before changing anything you're unsure about. They can usually check and fix permissions for you.
Never set permissions to 777, even temporarily. WordPress's documentation says no folders should ever be 777,3 since it lets other users on the server change your files. Some hosts also refuse to run files with such open permissions, which can cause errors of its own.
Check security plugins
Security plugins are one of the most common causes of 403 errors in WordPress. They can block your IP address after failed login attempts, restrict parts of the admin area or apply rules that clash with your server.
If you can still reach the dashboard, check the plugin's own logs or blocked-IP list first. You may be able to unblock yourself or allowlist your IP address without switching anything off. Otherwise, deactivate your security plugins one at a time under Plugins → Installed Plugins, checking after each whether the 403 clears.
If you're locked out of the dashboard, connect via SFTP or your hosting file manager, go to wp-content/plugins/ and rename the security plugin's folder (for example, from plugin-name to plugin-name-disabled). WordPress can then no longer load it. Try the site again.
This switches off the protection that plugin provides, so don't leave it like that. Once you've found the cause, rename the folder back, check the plugin is active again under Plugins and adjust its settings so it doesn't block you again. If you're locked out of the admin area entirely, our guide to regaining access to WordPress admin covers other ways back in.
Check your theme
Occasionally a theme causes a 403 through its own access rules. To test this, switch temporarily to a default WordPress theme.
If you can reach the dashboard, go to Appearance → Themes and activate a default theme. If you're locked out, rename your active theme's folder inside wp-content/themes/. WordPress then switches to its default theme, if one is installed.4
Either way, this is a real theme change that visitors will see, so do it at a quiet time or on a staging copy. When you've finished, reactivate your own theme under Appearance → Themes (renaming its folder back first if you renamed it) and check your menus and widgets are still in place.
Check server firewalls
Server firewalls such as ModSecurity can block genuine requests that happen to match one of their rules. This often happens when submitting forms with certain content, saving posts containing particular code or making lots of quick requests to the admin area.
You can't see or change these rules from WordPress. Your hosting provider can check the server's firewall logs and allow a request that's been blocked by mistake. If you've recently changed location or network, your new IP address may also have been caught by a blocklist.
The same firewall rules can cause other confusing errors. When they block the block editor, you see "Updating failed. The response is not a valid JSON response" (see our JSON response guide). When they block uploads, you get media upload errors. And when they block payment gateways, orders can get stuck on Pending payment.
Check hotlink protection
Some hosts offer hotlink protection, which stops other sites from displaying your images and files. If it's set up too broadly, it can also block requests from your own site, causing a 403. If you think this might be the cause, ask your hosting provider to review the rules.
Still seeing a 403?
Your hosting provider should be your first contact for a persistent 403, since they can see server logs and firewall settings that aren't visible from WordPress. If you need more help, my WordPress development service and emergency WordPress support cover permission problems, configuration issues and security plugin conflicts.
403 Forbidden, MDN Web Docs. ↩
Apache HTTPD / .htaccess, WordPress Advanced Administration Handbook. ↩
Changing file permissions, WordPress Advanced Administration Handbook. ↩ ↩
theme.php (validate_current_theme), WordPress source code on GitHub. ↩