"403 Forbidden" on your WordPress site: what it means and how to fix it

A 403 Forbidden page means the server found the page and refused to show it. On WordPress the cause is almost always one of four things: file permissions, a bad .htaccess file, a security plugin, or your host's firewall.

What to do, in order

  1. Check if it is every page or one. If only /wp-admin is blocked, suspect a security plugin or your host's firewall. If the whole site is blocked, suspect .htaccess or permissions.
  2. Rename .htaccess. In your host's file manager, rename .htaccess in the site folder to .htaccess-old. Load the site. If it works, go to Settings, Permalinks in WordPress and press Save. That writes a clean file.
  3. Turn off plugins without logging in. Rename the folder wp-content/plugins to plugins-off. If the site comes back, rename it back and switch plugins off one at a time. Security plugins such as Wordfence and iThemes are the usual cause.
  4. Fix permissions. Folders should be 755 and files 644. wp-config.php can be 640 or 600. A 403 often follows a migration that set everything to 600 or 700.
  5. Ask your host. If none of the above works, the block is on their side, often ModSecurity. Send them the exact address and time you saw the error and ask for the firewall log entry.

Check it yourself

Run curl -sI https://yourdomain.com. A 403 on the first line with a server: cloudflare header means Cloudflare is blocking you, not WordPress. Check the Security, Events page in Cloudflare.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.