What a WordPress 403 Forbidden error means
A 403 is an access decision rather than a missing-page message. The server received a valid request and knows which resource was requested, but its current rules do not permit that request to continue. Re-entering a WordPress password will not necessarily help because the restriction may be enforced before WordPress authentication runs.
The scope gives an important clue. A 403 on one file can point to permissions or a specific security rule. A block affecting wp-admin, REST API requests or form submissions may come from a WordPress security plugin, web application firewall or hosting rule. A site-wide 403 after a migration can indicate ownership, permissions or server configuration.
Before editing .htaccess, changing plugins or modifying permissions, take a full backup of the website files and database.
Common causes of a WordPress 403 error
On Apache hosting, .htaccess rules can deny access to a path or request pattern. Security plugins may add their own rules, while a host or CDN firewall can block an IP address, country, request signature or behaviour it considers suspicious.
Incorrect filesystem permissions or ownership can also prevent the web server from reading a file or entering a directory. This is particularly relevant after migrations, manual uploads or server-account changes. Do not respond by setting everything to fully writable permissions. Values such as 777 remove important protection and are not an appropriate general fix.
403 responses can also be deliberate. Sensitive files, server directories and administration endpoints may be intentionally protected. The objective is therefore to find the rule that is incorrectly blocking legitimate traffic, not to remove every access restriction.
How to fix a 403 Forbidden error in WordPress
- Find exactly what is blocked. Test the affected URL, the home page and wp-admin. If possible, check the browser network panel for the precise request returning 403. A blocked CSS file requires a different investigation from a blocked login or REST request.
- Check recent security changes. If the error followed a firewall, security-plugin, CDN or hosting-rule change, review that specific rule first. Do not permanently disable the whole security layer unless you have identified the cause and have another safe control in place.
- Test plugins where appropriate. If a WordPress security plugin is suspected, deactivate that specific plugin through wp-admin. If the dashboard is unavailable, use SFTP or the hosting file manager to rename its directory inside wp-content/plugins. Restore it after testing.
- Inspect .htaccess on Apache. Back up the file before editing it. If a recently added directive appears responsible, temporarily restore a known working copy or rename the file for a controlled test. Saving Settings, Permalinks can regenerate WordPress rewrite rules where the server permits it. Nginx does not read .htaccess, so Nginx access rules must be checked in server configuration instead.
- Check file ownership and permissions. Compare the affected files and directories with the host's recommended WordPress permissions. Correct only the entries that are wrong. Do not recursively make the entire site writable and do not use 777 as a shortcut.
- Check firewall and server logs. Hosting security logs, CDN events and web server logs may show the exact rule, IP restriction or request signature responsible for the denial. This is preferable to weakening security controls one by one.
When to get help with a WordPress 403 error
Stop and get technical help if correcting the error would require disabling firewall protection broadly, changing server ownership without understanding the hosting account, or editing access rules you cannot safely restore. An unexpected 403 after suspicious activity should also be investigated rather than simply bypassed.
Our Emergency Fix is £249 per incident with response within 2 working hours. Ongoing care plans start at £59 a month, with regular maintenance, backups and monitoring.