WordPress
Fix WordPress 403 Forbidden Error
Resolve a 403 Forbidden error blocking access to your WordPress site or admin area.
The Problem
403 errors on WordPress are almost always a permissions, .htaccess, or security-plugin/firewall rule blocking access — sometimes blocking you specifically, sometimes blocking everyone.
About this problem
A 403 Forbidden response means the server understood the request but refused it. On WordPress the usual reasons are restrictive file or folder permissions, rules in .htaccess, a security plugin blocking an address or request pattern, or a server firewall such as ModSecurity treating a normal request as an attack. It may affect everyone, only wp-admin, or only a single IP address.
People typically look for this after changing a security plugin, restoring a backup, moving host or editing .htaccess. It is also common when saving a post fails with a 403 because a firewall rule is reacting to the content.
What's Included
- Checking file/folder permissions for anything overly restrictive
- Reviewing .htaccess for rules causing the block
- Checking security plugins/server firewall rules that may be misfiring
- Confirming full access restored for both visitors and admin
What's NOT Included
- Fixing a hosting-level IP block (would need to be raised with your host)
- Security plugin reconfiguration beyond resolving this specific block
- Server firewall changes outside what WordPress controls
How It Works
- I find out exactly which URLs return 403 and for whom, and check the server access and error logs for the matching entries.
- I review file and folder permissions and ownership for anything too restrictive, including the index file and wp-admin.
- I inspect .htaccess for deny rules, rewrite rules or security snippets that block the request.
- I check security plugin settings and its blocked IP lists, and test with the plugin temporarily disabled to see whether it is the cause.
- I look for firewall rule IDs in the server logs if the block comes from ModSecurity or similar, and adjust only what is within the site's control.
- I confirm that visitors and administrators can reach the affected pages, and note what was changed.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Why am I getting a 403 Forbidden error on WordPress?
- Usually permissions, a .htaccess rule, a security plugin or a server firewall. Which one it is depends on the logs.
- Why does only wp-admin show a 403?
- Often a security plugin or firewall rule limiting the admin area, or an IP restriction in .htaccess. I check these first.
- What if my IP address is blocked by the host?
- That would need to be raised with your host, because it is outside the site's own configuration.
- Will you change my server firewall?
- Not beyond what WordPress controls. Server-level firewall changes are not part of this service.
- Will you reconfigure my security plugin?
- Only enough to resolve this block. A broader security review would be a separate service.
- Can a 403 be caused by a hacked site?
- Occasionally, yes. If I find signs of an infection I will tell you, and the malware service would apply.