You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WordPress上传文件后.htaccess的deny from all规则失效求助

Why WordPress-Uploaded Files Aren't Blocked (And How to Fix It)

Hey there, let's break down why your current .htaccess setup is only blocking FTP-uploaded files, and walk through the fixes to lock down all content in wp-content/uploads/ for good.

Possible Causes

  • Missing .htaccess in auto-generated subdirectories: WordPress automatically creates year/month subdirectories (like wp-content/uploads/2024/05) when you upload files via the WP dashboard. If you only added .htaccess to existing subdirectories, these dynamically created folders won't have the deny from all rule, so their files remain accessible.
  • Root .htaccess rules overriding subdirectory settings: If your site's root .htaccess has rewrite rules that explicitly allow access to wp-content/uploads/ (common with caching plugins or custom setups), Apache will prioritize those rules and skip executing the subdirectory .htaccess files entirely.
  • Apache AllowOverride restrictions (less likely): If your server's Apache config sets AllowOverride None for the wp-content/uploads/ directory, subdirectory .htaccess files are ignored. But since FTP-uploaded files are blocked, this is probably not the issue.

Fixes to Try

Instead of manually adding .htaccess to every subdirectory, set a single rule in your site's root .htaccess that blocks all access to wp-content/uploads/—this covers both existing and future auto-generated folders.

For Apache 2.2 and older:

<Directory "/full/path/to/your/wp-content/uploads">
    Deny from all
</Directory>

For Apache 2.4+ (most modern servers):

<Directory "/full/path/to/your/wp-content/uploads">
    Require all denied
</Directory>

If you prefer using rewrite rules instead (avoids editing Directory blocks):

RewriteRule ^wp-content/uploads/.*$ - [F,L]

This returns a 403 Forbidden response for any request to files or folders in uploads/.

2. Auto-Generate .htaccess in New WP Upload Directories

If you want to stick with per-subdirectory .htaccess files, add this code to your active theme's functions.php file. It will automatically create a .htaccess with the block rule whenever WordPress makes a new upload subdirectory:

add_action('wp_mkdir_p', 'auto_add_uploads_htaccess');
function auto_add_uploads_htaccess($dir) {
    $uploads_dir = wp_upload_dir();
    $uploads_base = $uploads_dir['basedir'];
    
    // Only target directories inside the main uploads folder
    if (strpos($dir, $uploads_base) === 0) {
        $htaccess_path = $dir . '/.htaccess';
        if (!file_exists($htaccess_path)) {
            // Use "Require all denied" instead if you're on Apache 2.4+
            file_put_contents($htaccess_path, 'deny from all');
            // Set secure file permissions
            chmod($htaccess_path, 0644);
        }
    }
}

3. Check for Conflicting Root .htaccess Rules

Open your root .htaccess and look for rules like this:

RewriteRule ^wp-content/uploads/ - [L]

The [L] flag tells Apache to stop processing further rules once this one runs, which means your subdirectory .htaccess blocks never get applied. If you find this rule, either delete it or move your upload-blocking rule above it in the file.

After making any changes, clear your browser cache and test accessing a WordPress-uploaded file—you should get a 403 Forbidden error now.

内容的提问来源于stack exchange,提问作者alex3410

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:15:01