Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress errorsWordPress 403 Forbidden Error: How to Fix It

WordPress 403 Forbidden Error: How to Fix It

A 403 Forbidden response means the server understood the request but is refusing access to the requested resource. On WordPress, the block can come from file permissions, web server rules, a security plugin, a firewall or hosting security controls.

The message you might see

403 Forbidden

Different wording, or a file path in the message? Paste it into our free error finder to see which plugin or theme it comes from.

What a WordPress 403 Forbidden error means

A 403 is an access decision rather than a missing-page message. The server received a valid request and knows which resource was requested, but its current rules do not permit that request to continue. Re-entering a WordPress password will not necessarily help because the restriction may be enforced before WordPress authentication runs.

The scope gives an important clue. A 403 on one file can point to permissions or a specific security rule. A block affecting wp-admin, REST API requests or form submissions may come from a WordPress security plugin, web application firewall or hosting rule. A site-wide 403 after a migration can indicate ownership, permissions or server configuration.

Before editing .htaccess, changing plugins or modifying permissions, take a full backup of the website files and database.

Common causes of a WordPress 403 error

On Apache hosting, .htaccess rules can deny access to a path or request pattern. Security plugins may add their own rules, while a host or CDN firewall can block an IP address, country, request signature or behaviour it considers suspicious.

Incorrect filesystem permissions or ownership can also prevent the web server from reading a file or entering a directory. This is particularly relevant after migrations, manual uploads or server-account changes. Do not respond by setting everything to fully writable permissions. Values such as 777 remove important protection and are not an appropriate general fix.

403 responses can also be deliberate. Sensitive files, server directories and administration endpoints may be intentionally protected. The objective is therefore to find the rule that is incorrectly blocking legitimate traffic, not to remove every access restriction.

How to fix a 403 Forbidden error in WordPress

  1. Find exactly what is blocked. Test the affected URL, the home page and wp-admin. If possible, check the browser network panel for the precise request returning 403. A blocked CSS file requires a different investigation from a blocked login or REST request.
  2. Check recent security changes. If the error followed a firewall, security-plugin, CDN or hosting-rule change, review that specific rule first. Do not permanently disable the whole security layer unless you have identified the cause and have another safe control in place.
  3. Test plugins where appropriate. If a WordPress security plugin is suspected, deactivate that specific plugin through wp-admin. If the dashboard is unavailable, use SFTP or the hosting file manager to rename its directory inside wp-content/plugins. Restore it after testing.
  4. Inspect .htaccess on Apache. Back up the file before editing it. If a recently added directive appears responsible, temporarily restore a known working copy or rename the file for a controlled test. Saving Settings, Permalinks can regenerate WordPress rewrite rules where the server permits it. Nginx does not read .htaccess, so Nginx access rules must be checked in server configuration instead.
  5. Check file ownership and permissions. Compare the affected files and directories with the host's recommended WordPress permissions. Correct only the entries that are wrong. Do not recursively make the entire site writable and do not use 777 as a shortcut.
  6. Check firewall and server logs. Hosting security logs, CDN events and web server logs may show the exact rule, IP restriction or request signature responsible for the denial. This is preferable to weakening security controls one by one.

When to get help with a WordPress 403 error

Stop and get technical help if correcting the error would require disabling firewall protection broadly, changing server ownership without understanding the hosting account, or editing access rules you cannot safely restore. An unexpected 403 after suspicious activity should also be investigated rather than simply bypassed.

Our Emergency Fix is £249 per incident with response within 2 working hours. Ongoing care plans start at £59 a month, with regular maintenance, backups and monitoring.

Common questions

Answers to the questions we hear most about this.

Can a WordPress security plugin cause a 403 Forbidden error?

Yes. A security plugin can deliberately return or trigger a 403 when a request matches one of its access or firewall rules. Check the plugin's events or logs and test the specific rule rather than permanently disabling all security.

Will changing file permissions fix a WordPress 403 error?

Only if incorrect filesystem permissions or ownership are causing the denial. Compare them with your host's recommended WordPress settings. Do not use 777 or make the whole site writable as a general fix.

Can .htaccess cause a 403 error in WordPress?

Yes, on Apache-based hosting. A deny rule, security directive or incorrect configuration in .htaccess can block access. Back up the file before testing changes. Nginx does not use .htaccess.

Site down or showing an error?

Call us now. Emergency Fix is £149 with a response within 2 working hours, and no fix means no fee.

Get website support