What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When WordPress cannot upload media or install an update, first identify the exact path and then correct its ownership and permissions. Open Tools → Site Health → Info → Filesystem Permissions; WordPress reports whether the main directory, wp-content, uploads, plugins, and a themes directory are writable. Inspect the failing path over SFTP, SSH, FTP, or your host’s file manager, back up the site, and apply the smallest safe change—normally 755 for directories and 644 for files.

Identify what is failing

Save the complete error message before changing anything. “Permission denied” during a media upload usually points to wp-content/uploads; a failed plugin or theme installation points to the relevant directory under wp-content/plugins or wp-content/themes. A failed core update can involve the WordPress installation directory itself. A 403 response may also involve the web server, a security policy, or an incorrect path rather than ordinary Unix mode bits.

The path matters because changing all of wp-content when only one subdirectory is affected increases risk and can damage a managed installation.

Check WordPress’s filesystem report

  1. Sign in to WordPress and open Tools → Site Health.
  2. Select the Info tab, expand Filesystem Permissions, and note every path marked writable or not writable.
  3. Keep that result beside the original error. After the repair, run the same check again.

This check tells you what WordPress can write, but it does not by itself prove that ownership, host security policies, or deployment links are correct.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect the path before changing permissions

Use SFTP, SSH, an FTP client, or the hosting control panel’s file manager. Confirm the installation path, the current owner and group, and the mode bits for the directory and its parent directories. A web process needs execute access on every parent directory to reach a file, and it needs write access on the target directory for uploads or package extraction.

Take a backup of the database and files first. On a self-managed server, identify the account that owns the site and the user or group used by PHP and the web server. On managed WordPress hosting, ask support to repair ownership if you cannot control it safely.

Use a least-privilege permissions baseline

Item Typical baseline Why it matters
Directories 755 Owner can read, write, and enter; others can read and enter.
Regular files 644 Owner can write; others can read without write access.
wp-config.php 400 or 440 where supported Restricts the configuration file to the owner and, with 440, an authorized group or web server.
Host-specific content directory 775/664 only when required Some hosting layouts need group write access; apply it only to the directory and files that need it.

WordPress’s hardening guidance uses 755 for directories and 644 for files. WordPress.com documents 775 or 755 for unmanaged directories and 644 for files. These are baselines, not a reason to make every path writable.

Correct one directory or file

With an SFTP or FTP client

  1. Open the exact directory reported by Site Health, such as wp-content/uploads.
  2. Open its permissions or attributes dialog.
  3. Set the directory to 755 and retry the original operation.
  4. If files inside have abnormal modes, set ordinary files to 644. Do not apply a directory mode to files or a file mode to directories.

With SSH

Replace the example path with the real absolute path. These commands affect only the specified tree, so verify it carefully before pressing Enter:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
find /path/to/your/wordpress/install/ -type d -exec chmod 755 {} ;
find /path/to/your/wordpress/install/ -type f -exec chmod 644 {} ;

For a single affected directory, target only that directory instead of the whole installation. If your host requires group write access, apply 775 to that specific directory and 664 only to the files that must be group-writable, after confirming the hosting design.

Fix ownership when modes look correct

Permissions can be numerically correct while the wrong account owns the files. The PHP or web-server process must be able to read the WordPress files and write to the particular content directory. On a self-managed server, use your host’s documented owner and group for the virtual host; do not guess a service account. On a managed host, request an ownership repair rather than recursively changing ownership or using a world-writable mode.

If the site uses symlinks, a deployment system, or a read-only release directory, inspect the link target and deployment configuration. A permission change on the visible path may not affect the actual target.

Retry and verify the original operation

  1. Repeat the exact media upload, plugin or theme installation, or update that failed.
  2. Return to Tools → Site Health → Info → Filesystem Permissions and confirm the affected path is writable.
  3. Check that the new file has the expected owner and mode, and that the operation did not make unrelated directories writable.

If the retry succeeds, leave the narrow permissions in place rather than broadening access “just in case.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When 755 and 644 do not solve it

  • Ownership mismatch: the web process cannot write even though the mode appears correct.
  • SELinux or another host security policy: mandatory controls can deny access independently of Unix modes.
  • Parent directory or disk issue: a parent lacks execute access, the filesystem is read-only, or the account has exhausted its quota.
  • Managed-host restriction: the platform controls plugin, theme, or symlinked directories.
  • Incomplete deployment: the path points to a release that is not writable by design.

Give your host the exact error, path, timestamp, and Site Health result. Ask it to restore the intended owner and writable directory; do not “fix” the problem by setting 777.

Permissions mistakes to avoid

  • Never leave 777 in place. It grants write access to everyone and can allow unauthorized modification or upload of executable code.
  • Do not recursively change all of wp-content when only uploads or a cache directory needs writing.
  • Do not alter directories controlled by WordPress.com, including symlinked plugins or themes; contact the platform instead.
  • Do not skip a backup. A broad recursive command can break the site if the path is wrong or the modes are reversed.

Choosing a repair method

Method Best for Scope and control Security considerations
SFTP Most self-managed sites without shell access Visual, path-by-path changes Good least-privilege control; verify the selected path.
SSH Administrators managing many files or a known tree Precise commands or recursive changes Fast but hazardous if the installation path is wrong.
FTP Hosts that provide FTP but not SFTP Manual file and folder attributes Use encrypted SFTP when the host offers it; avoid exposing credentials over plain FTP.
Host file manager or support Managed hosting and users without shell access Provider-specific; support can repair ownership Prefer provider repair for protected or symlinked paths.

The Bottom Line

Start with Site Health, inspect ownership and modes, correct only the failing path, and verify by repeating the failed operation. Use 755 for directories and 644 for files as the normal baseline, protect wp-config.php, and involve the host when ownership or platform security—not the mode bits—is blocking WordPress.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.