WordPress: 403 Forbidden on wp-admin, wp-login.php or admin-ajax.php
The server or a security layer refused access to WordPress admin URLs — file permissions, a security plugin/WAF rule, ModSecurity, or IP restrictions.
Seen on:
WordPress
Meaning
Common causes: .htaccess deny rules from hardening plugins, ModSecurity false positives (saving posts with code), hosting WAF blocking admin-ajax, wrong permissions on index.php, or an IP allowlist on wp-login.
Common causes
- Security plugin/WAF rule (Wordfence, iThemes, Cloudflare, ModSecurity)
- Restrictive .htaccess rules
- Wrong file permissions/ownership
- IP allowlist on wp-admin
⚡ Quick fix
- Check server error log / WAF events for the rule
- Temporarily rename the security plugin folder
- Reset file permissions (644 files, 755 dirs)
Detailed fix by platform
Linux
- bash
sudo tail -n 50 /var/log/apache2/error.log | grep -i -E 'modsecurity|denied' find /var/www/html -type d -exec chmod 755 {} \; && find /var/www/html -type f -exec chmod 644 {} \;
How to diagnose
- Logs — Which rule/denial?
- Plugins — Security plugins active?
- Scope — All admin or one action (saving, uploads)?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 0x800704EC 0x800704EC: This program is blocked by group policy (Windows Defender)
- 1005 Cloudflare Error 1005: Access denied — The owner of this website has banned the autonomous system number (ASN) your IP address is in
- 1006 Cloudflare Error 1006 / 1007 / 1008: Access denied — Your IP address has been banned
Most viewed in WordPress
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026