Blog
How to Fix a 500 Internal Server Error on Your WordPress Site
A 500 Internal Server Error feels like your WordPress site just slammed the door in your face.
The good news: a 500 error usually means something on the server failed, not that your whole website is gone. The trick is to stop guessing, make a backup first if you can, and work through the most likely causes in a safe order.
This guide walks through what a 500 error means, what to check first, and when it is time to stop poking around and ask your host or WordPress maintenance provider for help.
What a 500 Internal Server Error Means
A 500 Internal Server Error is a general server-side error. Your browser reached the website, but the server could not complete the request.
That is why it is frustrating. The message does not usually say, “This plugin broke,” or “Your PHP memory limit is too low.” It just tells you something failed behind the scenes.
On a WordPress site, common causes include:
- A plugin conflict
- A theme error
- A broken or misconfigured
.htaccessfile - PHP memory exhaustion
- A failed WordPress core, theme, or plugin update
- Incorrect file permissions
- A server configuration issue
- Malware or suspicious code triggering security rules
The fix depends on the cause. Do not start deleting files randomly. That often makes recovery harder.
Before You Touch Anything: Make the Site Safer to Troubleshoot
If your site is fully down, you may not be able to create a fresh WordPress backup from the dashboard. If you still have hosting access, check whether your host has a recent backup available before changing anything.
If you are on Ambrite’s Canadian cloud hosting, backups are included with every hosting plan. Starter includes weekly backups, while Business and Pro include daily backups. If you are on an Ambrite WordPress maintenance plan, daily backups are kept for 90 days.
Tip: If your site takes orders, bookings, quote requests, patient enquiries, or legal intake forms, be extra careful before restoring an older backup. A restore may roll back recent form entries, orders, content edits, or customer activity.
If you are not sure whether a restore will overwrite important data, pause and ask for help. A fast restore is useful, but restoring the wrong backup can create a second problem.
Step 1: Check Whether the Error Affects the Whole Site
Start by finding the scope of the problem. This tells you where to look first.
Test these areas:
- Your homepage
- A few inner pages
- Your WordPress admin login page
- The WordPress dashboard, if you can access it
- WooCommerce cart and checkout pages, if you run a store
If only one page shows a 500 error, the issue may be tied to that page’s content, shortcode, block, template, or form. If every page is down, the cause is more likely a plugin, theme, server rule, PHP issue, or WordPress-level failure.
If the public site works but the dashboard fails, look closely at admin-only plugins, security tools, custom dashboard code, or a recent update.
Step 2: Check the Error Logs
Error logs are often the fastest way to stop guessing. Your hosting control panel may have an “Errors,” “Error Log,” or similar section. Some hosts also keep PHP error logs inside the hosting account.
You are looking for clues like:
- A plugin folder name mentioned repeatedly
- A theme folder name mentioned repeatedly
- “Allowed memory size exhausted”
- “Fatal error”
- Permission denied messages
- ModSecurity or web application firewall blocks
If the log points to a specific plugin, do not assume the plugin is “bad.” It might conflict with another plugin, depend on a newer PHP setting, or fail because an update did not complete properly.
If you are not comfortable reading logs, copy the most recent error message into a support ticket with your host or maintenance provider. Do not paste sensitive credentials, API keys, private customer data, or full database dumps into a support request.
Step 3: Clear Caches, But Do Not Rely on That Alone
Sometimes you are seeing a cached version of an error page. Clear any cache you can access:
- Browser cache
- WordPress cache plugin cache
- Server-level cache
- CDN cache
This is worth doing, but it is not a full fix. If the server is still generating 500 errors after cache is cleared, you need to keep troubleshooting.
If you are using LiteSpeed Cache, WP Rocket, W3 Total Cache, or another caching plugin, check the official documentation for current cache-clearing steps. Plugin screens change often, and stale instructions can make things more confusing.
For a plain-language overview of how caching works, see WordPress Caching Explained: A Beginner's Guide.
Step 4: Disable Plugins Safely
Plugin conflicts are one of the most common causes of WordPress 500 errors. If you can still access the WordPress dashboard, go to the plugins screen and temporarily deactivate the most recently updated or installed plugin.
If the dashboard is unavailable, you can disable plugins through your hosting file manager or SFTP by renaming the plugin folder. The WordPress plugins are normally stored inside wp-content/plugins.
A safe testing approach is:
- Rename the suspected plugin folder.
- Reload the site in a private browser window.
- If the site comes back, you have found a likely cause.
- If nothing changes, restore the folder name and test the next suspect.
If you have no idea which plugin caused the problem, you can temporarily rename the whole plugins folder. WordPress will treat all plugins as inactive. If the site comes back, rename the folder back to plugins, then reactivate plugins carefully one by one.
When not to do this: Be careful on WooCommerce, membership, booking, LMS, or directory sites. Disabling plugins can affect orders, payments, bookings, logins, subscriptions, or access rules. If the site is business-critical, use a staging copy where possible.
If the 500 error appeared right after an update, this related guide may help: WordPress Update Broke My Site: What to Do.
Step 5: Switch to a Default Theme Temporarily
If plugins are not the cause, the active theme may be throwing a fatal error. This is more likely if you recently edited theme files, updated the theme, added custom code, or changed PHP versions.
If you can access the dashboard, switch temporarily to a default WordPress theme. If the site loads again, the issue is likely in the original theme or a theme-dependent feature.
If you cannot access the dashboard, a developer or host can switch the theme through the database or WP-CLI. If that sentence makes you nervous, do not force it. Theme switching at the database level is not the best place to learn on a live business site.
Custom themes can be excellent, but they should be maintained like any other code. If a theme has old functions, unsupported PHP code, or hardcoded plugin dependencies, a server update can expose problems that were hidden before.
Step 6: Regenerate the .htaccess File
On many Apache and LiteSpeed WordPress sites, the .htaccess file controls rewrite rules, redirects, and other behaviour. If it becomes corrupted, a 500 error can appear across the site.
A common test is to rename the existing .htaccess file to something like .htaccess-old, then reload the site. If the site comes back, log in to WordPress, go to the Permalinks settings screen, and save the settings to regenerate rewrite rules.
Do not delete the old file immediately. It may contain important redirects, security rules, or plugin rules that need to be reviewed and added back carefully.
If your site uses custom redirects for SEO, old URLs, landing pages, or bilingual content, preserve those rules. A working site with broken redirects can still create avoidable problems for users and search engines.
Step 7: Check PHP Memory and PHP Compatibility
If the error log says something like “Allowed memory size exhausted,” the site may be hitting its PHP memory limit. This can happen after adding a heavy plugin, importing content, running a backup, generating image thumbnails, or processing WooCommerce tasks.
Increasing memory may fix the immediate error, but it is not always the real solution. A plugin that constantly consumes too much memory may still need to be replaced, reconfigured, or investigated.
PHP compatibility is another common issue. If your host recently changed the PHP version, older plugins or themes may fail. The reverse can also happen: newer plugins may expect a more current PHP environment than your server provides.
In 2026, a healthy WordPress hosting setup should not be stuck on outdated server software. At the same time, changing PHP versions on a live site without testing can break older code. If your host offers staging, test there first.
Step 8: Review File Permissions
Incorrect file permissions can trigger server errors. This sometimes happens after a migration, manual file upload, security hardening attempt, or restore from backup.
You do not need to memorize every permission value to understand the concept. WordPress needs to read its own files, write to certain upload and cache folders, and protect sensitive files from public access.
Permissions that are too loose are a security risk. Permissions that are too strict can break the site.
If you suspect permissions are wrong, check with your host before bulk-changing everything. A careless “fix permissions” command can make the problem worse, especially on shared hosting or managed environments.
For more background, read WordPress File Permissions: A Security Guide.
Step 9: Check Security Rules and Firewalls
Sometimes a 500 error is caused by a security rule blocking a request. This can happen with web application firewalls, malware scanners, ModSecurity rules, brute-force protection, or CDN security settings.
For example, a form submission, admin save action, or plugin setting might trigger a rule that looks suspicious to the firewall. The rule might be correct, or it might be a false positive.
Do not simply turn off security tools and leave them off. That may get the page loading again, but it also removes protection.
A better approach is:
- Check logs to see which rule was triggered.
- Confirm whether the request was legitimate.
- Whitelist only what is necessary.
- Keep the broader firewall protection active.
Ambrite hosting includes Imunify360 protection on every plan, with real-time malware scanning, firewall protection, and brute-force protection. If a security rule is involved, the right fix is to review the event, not blindly disable protection.
Step 10: Look for Signs of Malware
A 500 error does not automatically mean your site is hacked. Plenty of ordinary plugin and server issues cause the same message.
Still, malware can cause fatal errors, especially if malicious code has been injected into WordPress files, theme files, plugin files, or the database. Malware cleanup attempts can also leave broken code behind if they are incomplete.
Warning signs include:
- Unknown admin users
- Strange redirects
- Spam pages appearing in Google
- Security warnings in the browser
- Unexpected files in WordPress folders
- Recently modified files you did not edit
If you see these signs, treat the site as compromised until proven otherwise. Do not just restore an old backup and move on unless you know when the infection started and how it got in.
Ambrite provides WordPress hack cleanup and malware removal for compromised sites. Hack cleanup is included free on the Complete maintenance plan. On Care and Growth, one-off cleanup starts at $499 CAD, depending on severity, and is usually finished within 24 to 48 hours.
Step 11: Restore from Backup Only When It Makes Sense
Restoring a backup can be the fastest fix for a 500 error, but it is not always the smartest first move.
A restore makes sense when:
- You know exactly when the site broke
- You have a clean backup from before that point
- No important orders, forms, bookings, or content changes will be lost
- You understand what caused the break and can avoid repeating it
A restore is risky when:
- The site may have been infected for a while
- The backup is untested
- You run WooCommerce or collect time-sensitive enquiries
- You do not know what data changed after the backup was created
If your site handles Canadian customer data, contact forms, orders, patient enquiries, or legal intake requests, think carefully before rolling back. A backup restore is a technical action, but it can have privacy and business consequences too.
If you want a deeper look at backup strategy, see How Daily Backups Protect Your Website.
Common Mistakes That Make 500 Errors Worse
When a site is down, it is tempting to try everything at once. That makes troubleshooting harder because you no longer know which change fixed or worsened the problem.
Avoid these mistakes:
- Deleting plugins instead of disabling them. Deleting can remove settings or data, depending on the plugin.
- Editing live code without a copy. One typo can turn a partial outage into a full outage.
- Restoring a random backup. You may overwrite recent orders, leads, or edits.
- Turning off security permanently. A temporary test is different from leaving the site exposed.
- Ignoring the logs. Logs often tell you where to look.
- Changing PHP versions repeatedly. Test methodically and record what you changed.
Keep notes as you work. Write down what you changed, when you changed it, and what happened. If you need help later, those notes save time.
When to Contact Your Host
Contact your hosting provider if:
- You cannot access hosting backups
- The error logs point to server-level issues
- The site broke after a server change
- You suspect PHP, permissions, firewall rules, or resource limits
- Multiple sites on the same hosting account are failing
A good support request is specific. Instead of “my site is broken,” send:
- The URL showing the 500 error
- When the issue started
- What changed recently
- Whether the WordPress admin works
- Any recent error log messages
- Whether you approve a backup restore, or want confirmation first
Ambrite support is handled by ticket and email, directly by the developer responsible for the hosting, maintenance, and security work. That keeps the troubleshooting trail in writing, which is useful when changes need to be tracked carefully.
When to Stop DIY Troubleshooting
Some 500 errors are simple. A plugin update fails, you disable the plugin, and the site returns.
Other cases are not worth gambling with, especially if the site is tied to revenue, client intake, bookings, or customer data.
Stop and get help if:
- You are about to edit the database directly
- You do not have a known-good backup
- The site processes WooCommerce orders
- The error appeared after suspicious activity
- You see unknown admin users or strange redirects
- You have already tried several fixes and the site is getting worse
There is no shame in stopping early. The cheapest fix is often the one done before the site has been changed beyond recognition.
How to Reduce 500 Errors in the Future
You cannot prevent every possible failure. WordPress depends on themes, plugins, hosting, PHP, databases, DNS, caching, and third-party services. Something can always go sideways.
But you can reduce the odds dramatically.
- Keep WordPress core, themes, and plugins updated.
- Remove plugins you no longer use.
- Use quality hosting with current PHP support and useful logs.
- Test major changes on staging before pushing live.
- Keep automatic backups, and know how restores work.
- Monitor uptime so you find out quickly when the site goes down.
- Use security monitoring and malware scanning.
- Document custom code, must-keep plugin versions, and critical integrations.
Ambrite’s WordPress maintenance and security plans include daily updates, daily backups kept for 90 days, 24/7 uptime monitoring, malware scanning, a global CDN, DDoS protection, daily speed checks, and support by email and client area. Growth and Complete add more hands-on checks, and Complete includes staging-tested updates plus form, cart, and checkout testing after major updates.
If your site is hosted elsewhere, maintenance can still be handled remotely. If the hosting itself is part of the problem, moving to a better environment may save you from fighting the same issue again next month.
Quick 500 Error Checklist
If you need the short version, work through this in order:
- Check whether the whole site is down or only one page.
- Confirm you have a usable backup before making changes.
- Check hosting error logs for plugin, theme, memory, permission, or firewall clues.
- Clear browser, plugin, server, and CDN caches.
- Temporarily disable the most likely plugin conflict.
- Test the active theme if plugins are not the cause.
- Rename and regenerate
.htaccessif appropriate. - Review PHP memory and PHP compatibility.
- Check file permissions carefully.
- Look for malware signs if anything seems suspicious.
- Restore from backup only when you understand what will be lost.
- Contact your host or maintenance provider if the issue is not clear.
A 500 error is fixable, but the best fix is the one that identifies the cause, not just the symptom. If you need help with a WordPress site that is down, unstable, or throwing server errors, you can contact Ambrite and include your website address, what changed recently, and any error messages you have.
This article was written with the help of AI and reviewed by Ambrite. Pricing, features, and technical details may change, so always verify with official sources before making decisions.
Was this article useful?
Related Articles
Your hosting location matters more than you think. Beyond the obvious speed benefits, hosting...
Setting up professional email is like finally getting business cards that don't say "Gmail" on...
Setting up WordPress on cloud hosting isn't rocket science, but doing it wrong can turn your...
That moment when your website crashes because you ran out of disk space? Or when your host...
Your WordPress site just lost another visitor. They waited 3 seconds for your homepage to load,...
