WP-INCLUDES文件夹返回403错误求助(WordPress+IIS+Cloudflare环境)
Hey there, let’s work through this wp-includes 403 error you’re facing on your Windows/IIS + Cloudflare WordPress setup. I’ve troubleshooted similar issues before, so here are targeted fixes to try:
1. Check IIS Request Filtering Rules
IIS often has default filtering that might block access to wp-includes. Here’s what to verify:
- Open IIS Manager, navigate to your site, and select Request Filtering.
- Go to the Hidden Segments tab—ensure
wp-includesisn’t listed here (if it is, remove it). - Check the File Name Extensions tab to confirm
.phpis allowed (not blocked). - Look through the Rules tab for any custom rules that explicitly deny access to
/wp-includes/paths.
2. Audit Cloudflare Security Rules
Cloudflare’s WAF or bot protection might be flagging wp-includes requests as malicious:
- Log into your Cloudflare dashboard, go to Security > WAF, and check the Events tab for any blocked requests targeting
/wp-includes/. - If you see triggered rules, you can either:
- Temporarily disable the WAF (for testing only) to confirm it’s the culprit.
- Create a custom WAF rule to allow legitimate requests to
/wp-includes/*(narrow it down to avoid security risks).
- Also check Security > Bots to ensure legitimate traffic isn’t being categorized as a harmful bot and blocked.
3. Validate Your Web.config File
WordPress on IIS relies on web.config for rewrites and permissions—incorrect rules here can cause 403s:
- Open your site’s root
web.configfile and look for any rules that deny access towp-includes. For example, avoid rules like:<rule name="Block wp-includes" stopProcessing="true"> <match url="^wp-includes/" /> <action type="CustomResponse" statusCode="403" /> </rule> - If you’re unsure, replace your
web.configwith the official WordPress IIS template (available in WordPress documentation) to rule out bad custom rules.
4. Double-Check File System Permissions
Even if you’ve set permissions, Windows/IIS has nuanced settings to confirm:
- Right-click the
wp-includesfolder, go to Properties > Security. - Ensure the IIS application pool identity (usually
IIS_IUSRSor a custom app pool user) has Read & Execute, List Folder Contents, and Read permissions. - Check the Advanced settings to make sure:
- Permissions are inherited from parent folders (unless you have a specific reason to override).
- No "Deny" permissions are present that would override allowed permissions.
5. Resolve SSL Mode Conflicts Between Cloudflare and IIS
Mismatched SSL settings can lead to blocked requests:
- In Cloudflare, go to SSL/TLS > Overview and check your SSL mode:
- If using Full or Strict, ensure your IIS server has a valid SSL certificate (either a Cloudflare Origin Certificate or a trusted third-party cert).
- If using Flexible, make sure IIS is configured to accept HTTP requests (note: this is less secure, but useful for testing).
- Verify your IIS site has a valid HTTPS binding on port 443 with the correct certificate.
6. Test Directly (Bypass Cloudflare)
To isolate whether the issue is with Cloudflare or your server:
- Edit your local
hostsfile (located atC:\Windows\System32\drivers\etc\hosts) to map your domain to your server’s public IP address. - Clear your browser cache and visit your site—if the wp-includes 403 error goes away, the problem is definitely in Cloudflare’s configuration. If it persists, focus on IIS/WordPress settings.
If none of these fixes work, enabling IIS Failed Request Tracing or checking Cloudflare’s request logs can help pinpoint the exact reason for the 403 block.
内容的提问来源于stack exchange,提问作者Nilson Machado

