WordPress FTP — Upload Themes, Plugins, and Files
There's a common misconception here: WordPress has no built-in FTP of its own. Your WordPress files live on your web host's server, and the way to reach them directly is to connect to your hosting account's FTP or SFTP. With FilePort Pro you connect to that FTP/SFTP account from the browser — no software to install — and upload themes, plugins, and media straight into the right folder.
Connect Now — upload to your WordPress hosting
WordPress has no FTP of its own — you use your host's
WordPress is software installed on a web server that your hosting provider runs. It doesn't include an FTP server, and it doesn't hold your FTP credentials — the FTP account is your hosting account's, created in the same control panel where you manage email, databases, and domains. If you use cPanel, that's under Files → FTP Accounts (see the cPanel FTP guide). If your host uses another panel, the principle is the same: look for an FTP section in your hosting control panel, where the FTP hostname, account username, and password (or a way to set one) live. When "WordPress asks for FTP," what it's really asking for is these hosting-account FTP credentials so it can write files to the server.
Where to find your WordPress FTP credentials
Because WordPress itself has no credentials screen, go to your hosting control panel — not the WordPress dashboard. Sign in to your hosting account and look for the FTP section:
- cPanel hosts — go to Files → FTP Accounts. That screen shows your FTP hostname (commonly your domain or
ftp.yourdomain.com), your FTP account usernames, and a way to set or reset each password. - Other panels — Bluehost, Hostinger, SiteGround, and similar hosts each keep an FTP section in their own dashboard; use the location for your specific host.
- Note the host, username, and port your account supports (FTP 21, SFTP 22, or FTPS 990) — you'll enter these in your client.
Your provider-specific guide is the fastest reference — see the cPanel FTP, Bluehost FTP, Hostinger, or SiteGround pages for your host's exact location.
Why upload WordPress files with FTP at all
The WordPress dashboard can install themes, plugins, and uploads on its own — usually. But there are real situations where FTP is the reliable path:
- The dashboard "Install Now" button fails — often because WordPress can't write to the server's files, or the host blocks the direct download. Uploading the theme or plugin folder over FTP puts the files in place directly.
- A file-size limit blocks a large upload — hosting environments cap uploads (for example 2 MB or 8 MB). A large theme, plugin, backup, or media file can hit that limit in the dashboard but uploads fine straight to the right folder over FTP.
- You want to move many files at once — FTP gives you a real file browser with drag-and-drop uploads, whole-folder navigation, and downloads of folders as a ZIP archive.
Uploading over FTP bypasses the dashboard's size limits but not the server's own settings — if a file is genuinely rejected by the server configuration, that's a hosting-side limit to change there.
Where WordPress files live on the server
Inside your WordPress installation, the files you'll touch over FTP live in the wp-content folder:
- Theme files —
wp-content/themes/. Each theme is a subfolder; to upload a theme, put its folder here (for examplewp-content/themes/my-theme/). - Plugin files —
wp-content/plugins/. Each plugin is a subfolder here. - Uploads and media —
wp-content/uploads/. Images you find in Media live here, usually organized by year and month.
Your WordPress installation itself normally sits in your site's document root (the public_html folder on many shared hosts). If you're ever unsure where the WordPress root is on your particular account, confirm with your hosting provider rather than guessing before you overwrite anything.
WordPress file permissions gotcha
WordPress is sensitive to file permissions, and a common source of "can't upload" or blank-screen problems. The common convention is files set to 644 and directories set to 755. That means the owner can read and write, and everyone else can read files and list directories. A few practical notes: avoid setting files to 777 (world-writable) except as a short-lived test, and don't set them too restricted either — if wp-content/uploads isn't writable, uploading media through the dashboard will fail. When you upload files with an FTP client, check the permission set if your host's defaults leave folders unusable.
FTP vs FTPS vs SFTP for WordPress
WordPress hosting can offer three different file-transfer protocols, and they use different ports:
- FTP — port 21. Plain FTP sends your password and files unencrypted by protocol design.
- FTPS — port 990. FTP wrapped in TLS, so it encrypts the connection (explicit FTPS commonly uses port 21 as well).
- SFTP — port 22. SFTP runs over SSH and encrypts everything. It's preferred when your host offers it — most managed WordPress and VPS hosts do, while some plain shared hosting plans may only offer FTP.
If your hosting account offers SFTP, use it — your web SFTP client connects over port 22. If only plain FTP is available, FilePort Pro's web FTP client connects on port 21, warns you about the unencrypted connection, and recommends SFTP when you have it.
Connect to your WordPress hosting from the browser
With the host and credentials in hand, uploading to WordPress is quick:
- Open FilePort Pro — it lives in the browser, so there's nothing to install.
- Choose the protocol — FTP on port 21 (or FTPS on 990), or SFTP on port 22 if your host offers it.
- Enter the host, username, and password from your hosting control panel's FTP section.
- Click Connect — you land in the file list. Navigate to
wp-content/themes,wp-content/plugins, orwp-content/uploads, and upload by clicking or dragging files in.
Then, from the WordPress dashboard, go to Appearance → Themes or Plugins — the theme or plugin you placed in the right folder will show up there ready to activate.
Common WordPress FTP errors and fixes
- "Connection refused" — nothing is answering on the port, often port 21. Check the protocol and port your host expects, and that your hosting account's FTP is active. On firewalled or port-restricted networks, passive mode for FTP can matter too.
- "Connection timed out" — traffic is being dropped, usually a firewall (local or host-side) blocking the port. Confirm the port is reachable from the network you're on, and check the FTP port checker below.
- "Authentication failed" — the username or password is wrong. Reset your FTP password in the hosting control panel, and use the exact username shown there (some hosts append the domain, like
user@example.com). - "WordPress still asks for credentials to install" — that's not an FTP connection failure. WordPress is asking for your host's FTP credentials because it can't write files directly; enter those, or upload the plugin/theme to
wp-content/pluginsorwp-content/themesover FTP instead. - Files upload but the site breaks — usually a permissions or wrong-folder problem. Check files are 644 and directories 755, and that the theme/plugin went into the correct subfolder.
Not sure the port is open? Use the FTP port checker.
A note on WordPress FTP security
Because FilePort Pro relays your connection, your hosting credentials pass through our server to reach yours — never "credentials never leave your browser." They're held in memory only for the active session, never stored, never logged, and the session ends when you disconnect or after about 15 minutes of inactivity. Your WordPress files can amount to your whole site, so prefer SFTP (port 22) whenever your host offers it; avoid plain FTP (port 21) on networks you don't trust, since it sends your password in cleartext by protocol design. See our security page for how FilePort Pro handles your credentials.
Frequently asked questions
Does WordPress have a built-in FTP client?
No. WordPress itself has no built-in FTP client and no FTP server — your WordPress files live on your web host's server, and you reach them by connecting to your hosting account's FTP or SFTP. The credentials you use are your hosting account's, not WordPress's.
Where do WordPress files live on the server?
Themes go in wp-content/themes, plugins in wp-content/plugins, and uploads (images and media) in wp-content/uploads. These folders are inside your WordPress installation, which is usually in your site's document root such as public_html. If you're unsure, check your hosting provider's setup.
Why does WordPress keep asking for FTP credentials when I install a plugin?
Because WordPress can't write to the web server's files directly, it asks for your hosting account's FTP/SFTP credentials to copy the files. That request is addressed to your host's FTP server, not WordPress — use the FTP credentials from your hosting control panel, or install the plugin by uploading the folder to wp-content/plugins over FTP.
What port does WordPress FTP use?
It depends on the protocol your hosting account supports: plain FTP uses port 21, FTPS uses port 990, and SFTP uses port 22. SFTP is preferred when your host offers it because it encrypts everything — your password and files — whereas plain FTP sends them unencrypted.
Why does my large theme or plugin upload fail in WordPress?
The WordPress dashboard uploads are limited by hosting settings, typically a size cap like 2 MB or 8 MB. Uploading the plugin or theme folder directly to wp-content/plugins or wp-content/themes over FTP bypasses the dashboard's size limit — though a hard server-side limit would still need to be raised in the hosting configuration.
What file permissions do WordPress files need?
The common convention is files set to 644 and directories set to 755. That lets the owner read and write, and others can read files and list directories. Avoid 777 (world-writable) except as a temporary test, and avoid permissions that are too restrictive, which can break the uploads folder.
More host guides
WordPress runs on your hosting account, so the exact credentials flow from your provider's control panel. See the matching guide for your host:
- cPanel FTP — upload without the File Manager
- GoDaddy FTP & SFTP — where to find credentials
- Bluehost FTP & SFTP — how to upload files
- Hostinger SFTP & FTP — hPanel credentials
- SiteGround SFTP & FTP — set up in Site Tools
- DreamHost SFTP & FTP — connect from the browser
- Plesk FTP & SFTP — access & find credentials
- Cloudways SFTP — upload files from the browser
- DigitalOcean SFTP — upload files to a Droplet
- AWS Lightsail SFTP — upload from the browser
- AWS EC2 SFTP — connect from the browser
- FTP connection errors — why they happen and how to fix them
- SFTP connection errors — host keys, publickey, refused, and timeouts
- FileZilla alternatives — free desktop and no-install options
For more on browser-based transfers, see the web SFTP client and the web FTP client. Questions about what we store? Read the privacy policy or the security page.
Get started — upload to WordPress from your browser
No install, no sign-up, no credentials stored. Connect Now — access your WordPress files
Prefer an encrypted transfer? Use SFTP if your host offers it, or plain FTP on port 21 if not. Questions about what we store? Read the privacy policy.