You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WP-INCLUDES文件夹返回403错误求助(WordPress+IIS+Cloudflare环境)

Fixing WP-INCLUDES 403 Error on WordPress (Windows/IIS + Cloudflare)

Hey there, let’s work through this wp-includes 403 error you’re facing on your Windows/IIS + Cloudflare WordPress setup. I’ve troubleshooted similar issues before, so here are targeted fixes to try:

1. Check IIS Request Filtering Rules

IIS often has default filtering that might block access to wp-includes. Here’s what to verify:

  • Open IIS Manager, navigate to your site, and select Request Filtering.
  • Go to the Hidden Segments tab—ensure wp-includes isn’t listed here (if it is, remove it).
  • Check the File Name Extensions tab to confirm .php is allowed (not blocked).
  • Look through the Rules tab for any custom rules that explicitly deny access to /wp-includes/ paths.

2. Audit Cloudflare Security Rules

Cloudflare’s WAF or bot protection might be flagging wp-includes requests as malicious:

  • Log into your Cloudflare dashboard, go to Security > WAF, and check the Events tab for any blocked requests targeting /wp-includes/.
  • If you see triggered rules, you can either:
    • Temporarily disable the WAF (for testing only) to confirm it’s the culprit.
    • Create a custom WAF rule to allow legitimate requests to /wp-includes/* (narrow it down to avoid security risks).
  • Also check Security > Bots to ensure legitimate traffic isn’t being categorized as a harmful bot and blocked.

3. Validate Your Web.config File

WordPress on IIS relies on web.config for rewrites and permissions—incorrect rules here can cause 403s:

  • Open your site’s root web.config file and look for any rules that deny access to wp-includes. For example, avoid rules like:
    <rule name="Block wp-includes" stopProcessing="true">
      <match url="^wp-includes/" />
      <action type="CustomResponse" statusCode="403" />
    </rule>
    
  • If you’re unsure, replace your web.config with the official WordPress IIS template (available in WordPress documentation) to rule out bad custom rules.

4. Double-Check File System Permissions

Even if you’ve set permissions, Windows/IIS has nuanced settings to confirm:

  • Right-click the wp-includes folder, go to Properties > Security.
  • Ensure the IIS application pool identity (usually IIS_IUSRS or a custom app pool user) has Read & Execute, List Folder Contents, and Read permissions.
  • Check the Advanced settings to make sure:
    • Permissions are inherited from parent folders (unless you have a specific reason to override).
    • No "Deny" permissions are present that would override allowed permissions.

5. Resolve SSL Mode Conflicts Between Cloudflare and IIS

Mismatched SSL settings can lead to blocked requests:

  • In Cloudflare, go to SSL/TLS > Overview and check your SSL mode:
    • If using Full or Strict, ensure your IIS server has a valid SSL certificate (either a Cloudflare Origin Certificate or a trusted third-party cert).
    • If using Flexible, make sure IIS is configured to accept HTTP requests (note: this is less secure, but useful for testing).
  • Verify your IIS site has a valid HTTPS binding on port 443 with the correct certificate.

6. Test Directly (Bypass Cloudflare)

To isolate whether the issue is with Cloudflare or your server:

  • Edit your local hosts file (located at C:\Windows\System32\drivers\etc\hosts) to map your domain to your server’s public IP address.
  • Clear your browser cache and visit your site—if the wp-includes 403 error goes away, the problem is definitely in Cloudflare’s configuration. If it persists, focus on IIS/WordPress settings.

If none of these fixes work, enabling IIS Failed Request Tracing or checking Cloudflare’s request logs can help pinpoint the exact reason for the 403 block.

内容的提问来源于stack exchange,提问作者Nilson Machado

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 10:05:49