403 Forbidden wp-admin 📝 WordPress

WordPress: 403 Forbidden on wp-admin, wp-login.php or admin-ajax.php

The server or a security layer refused access to WordPress admin URLs — file permissions, a security plugin/WAF rule, ModSecurity, or IP restrictions.

Seen on: WordPress

Meaning

Common causes: .htaccess deny rules from hardening plugins, ModSecurity false positives (saving posts with code), hosting WAF blocking admin-ajax, wrong permissions on index.php, or an IP allowlist on wp-login.

Common causes

  • Security plugin/WAF rule (Wordfence, iThemes, Cloudflare, ModSecurity)
  • Restrictive .htaccess rules
  • Wrong file permissions/ownership
  • IP allowlist on wp-admin

⚡ Quick fix

  1. Check server error log / WAF events for the rule
  2. Temporarily rename the security plugin folder
  3. Reset file permissions (644 files, 755 dirs)

Detailed fix by platform

Linux

  1. bash
    sudo tail -n 50 /var/log/apache2/error.log | grep -i -E 'modsecurity|denied'
    find /var/www/html -type d -exec chmod 755 {} \; && find /var/www/html -type f -exec chmod 644 {} \;

How to diagnose

  1. Logs — Which rule/denial?
  2. Plugins — Security plugins active?
  3. Scope — All admin or one action (saving, uploads)?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.