WordPress FTP — Upload Themes, Plugins, and Files

There's a common misconception here: WordPress has no built-in FTP of its own. Your WordPress files live on your web host's server, and the way to reach them directly is to connect to your hosting account's FTP or SFTP. With FilePort Pro you connect to that FTP/SFTP account from the browser — no software to install — and upload themes, plugins, and media straight into the right folder.

Connect Now — upload to your WordPress hosting

WordPress has no FTP of its own — you use your host's

WordPress is software installed on a web server that your hosting provider runs. It doesn't include an FTP server, and it doesn't hold your FTP credentials — the FTP account is your hosting account's, created in the same control panel where you manage email, databases, and domains. If you use cPanel, that's under Files → FTP Accounts (see the cPanel FTP guide). If your host uses another panel, the principle is the same: look for an FTP section in your hosting control panel, where the FTP hostname, account username, and password (or a way to set one) live. When "WordPress asks for FTP," what it's really asking for is these hosting-account FTP credentials so it can write files to the server.

Where to find your WordPress FTP credentials

Because WordPress itself has no credentials screen, go to your hosting control panel — not the WordPress dashboard. Sign in to your hosting account and look for the FTP section:

  1. cPanel hosts — go to Files → FTP Accounts. That screen shows your FTP hostname (commonly your domain or ftp.yourdomain.com), your FTP account usernames, and a way to set or reset each password.
  2. Other panels — Bluehost, Hostinger, SiteGround, and similar hosts each keep an FTP section in their own dashboard; use the location for your specific host.
  3. Note the host, username, and port your account supports (FTP 21, SFTP 22, or FTPS 990) — you'll enter these in your client.

Your provider-specific guide is the fastest reference — see the cPanel FTP, Bluehost FTP, Hostinger, or SiteGround pages for your host's exact location.

Why upload WordPress files with FTP at all

The WordPress dashboard can install themes, plugins, and uploads on its own — usually. But there are real situations where FTP is the reliable path:

Uploading over FTP bypasses the dashboard's size limits but not the server's own settings — if a file is genuinely rejected by the server configuration, that's a hosting-side limit to change there.

Where WordPress files live on the server

Inside your WordPress installation, the files you'll touch over FTP live in the wp-content folder:

Your WordPress installation itself normally sits in your site's document root (the public_html folder on many shared hosts). If you're ever unsure where the WordPress root is on your particular account, confirm with your hosting provider rather than guessing before you overwrite anything.

WordPress file permissions gotcha

WordPress is sensitive to file permissions, and a common source of "can't upload" or blank-screen problems. The common convention is files set to 644 and directories set to 755. That means the owner can read and write, and everyone else can read files and list directories. A few practical notes: avoid setting files to 777 (world-writable) except as a short-lived test, and don't set them too restricted either — if wp-content/uploads isn't writable, uploading media through the dashboard will fail. When you upload files with an FTP client, check the permission set if your host's defaults leave folders unusable.

FTP vs FTPS vs SFTP for WordPress

WordPress hosting can offer three different file-transfer protocols, and they use different ports:

If your hosting account offers SFTP, use it — your web SFTP client connects over port 22. If only plain FTP is available, FilePort Pro's web FTP client connects on port 21, warns you about the unencrypted connection, and recommends SFTP when you have it.

Connect to your WordPress hosting from the browser

With the host and credentials in hand, uploading to WordPress is quick:

  1. Open FilePort Pro — it lives in the browser, so there's nothing to install.
  2. Choose the protocol — FTP on port 21 (or FTPS on 990), or SFTP on port 22 if your host offers it.
  3. Enter the host, username, and password from your hosting control panel's FTP section.
  4. Click Connect — you land in the file list. Navigate to wp-content/themes, wp-content/plugins, or wp-content/uploads, and upload by clicking or dragging files in.

Then, from the WordPress dashboard, go to Appearance → Themes or Plugins — the theme or plugin you placed in the right folder will show up there ready to activate.

Common WordPress FTP errors and fixes

Not sure the port is open? Use the FTP port checker.

A note on WordPress FTP security

Because FilePort Pro relays your connection, your hosting credentials pass through our server to reach yours — never "credentials never leave your browser." They're held in memory only for the active session, never stored, never logged, and the session ends when you disconnect or after about 15 minutes of inactivity. Your WordPress files can amount to your whole site, so prefer SFTP (port 22) whenever your host offers it; avoid plain FTP (port 21) on networks you don't trust, since it sends your password in cleartext by protocol design. See our security page for how FilePort Pro handles your credentials.

Frequently asked questions

Does WordPress have a built-in FTP client?

No. WordPress itself has no built-in FTP client and no FTP server — your WordPress files live on your web host's server, and you reach them by connecting to your hosting account's FTP or SFTP. The credentials you use are your hosting account's, not WordPress's.

Where do WordPress files live on the server?

Themes go in wp-content/themes, plugins in wp-content/plugins, and uploads (images and media) in wp-content/uploads. These folders are inside your WordPress installation, which is usually in your site's document root such as public_html. If you're unsure, check your hosting provider's setup.

Why does WordPress keep asking for FTP credentials when I install a plugin?

Because WordPress can't write to the web server's files directly, it asks for your hosting account's FTP/SFTP credentials to copy the files. That request is addressed to your host's FTP server, not WordPress — use the FTP credentials from your hosting control panel, or install the plugin by uploading the folder to wp-content/plugins over FTP.

What port does WordPress FTP use?

It depends on the protocol your hosting account supports: plain FTP uses port 21, FTPS uses port 990, and SFTP uses port 22. SFTP is preferred when your host offers it because it encrypts everything — your password and files — whereas plain FTP sends them unencrypted.

Why does my large theme or plugin upload fail in WordPress?

The WordPress dashboard uploads are limited by hosting settings, typically a size cap like 2 MB or 8 MB. Uploading the plugin or theme folder directly to wp-content/plugins or wp-content/themes over FTP bypasses the dashboard's size limit — though a hard server-side limit would still need to be raised in the hosting configuration.

What file permissions do WordPress files need?

The common convention is files set to 644 and directories set to 755. That lets the owner read and write, and others can read files and list directories. Avoid 777 (world-writable) except as a temporary test, and avoid permissions that are too restrictive, which can break the uploads folder.

More host guides

WordPress runs on your hosting account, so the exact credentials flow from your provider's control panel. See the matching guide for your host:

For more on browser-based transfers, see the web SFTP client and the web FTP client. Questions about what we store? Read the privacy policy or the security page.

Get started — upload to WordPress from your browser

No install, no sign-up, no credentials stored. Connect Now — access your WordPress files

Prefer an encrypted transfer? Use SFTP if your host offers it, or plain FTP on port 21 if not. Questions about what we store? Read the privacy policy.