{"id":18994396,"date":"2026-08-15T13:56:27","date_gmt":"2026-08-15T13:56:27","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/access-denied-invalid-request\/"},"modified":"2026-08-15T13:56:27","modified_gmt":"2026-08-15T13:56:27","slug":"access-denied-invalid-request","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/access-denied-invalid-request\/","title":{"rendered":"Access denied. Invalid request."},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hello,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">since the automatic <strong>update of Advanced File Manager from version 5.4.12 to 5.4.13<\/strong>, write operations in the frontend file manager no longer work on our WordPress site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The file manager itself loads correctly. Users can access their assigned personal directories and read permissions are working as expected. The directories also have the correct filesystem permissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, any attempt to perform a write operation, for example creating a new folder, fails with the following message:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Access denied.<br \/>Invalid request. Please reload.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I can reproduce the issue with different WordPress users and different personal directories, so it does not appear to be related to a specific user or directory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The AJAX request for creating a directory is sent correctly, for example with:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>cmd=mkdir<\/code><br \/><code>name=Neuer Ordner<\/code><br \/><code>target=l1_Lw<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The server responds with:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">{<br \/>&#8220;error&#8221;: [<br \/>&#8220;errPerm&#8221;,<br \/>&#8220;Invalid request. Please reload.&#8221;<br \/>],<br \/>&#8220;csrfReload&#8221;: true<br \/>}<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The initial request to the file manager works correctly and reports the root directory with:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>read: 1<\/code><br \/><code>write: 1<\/code><br \/><code>isroot: 1<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The problem appeared immediately after the automatic update from <strong>Advanced File Manager 5.4.12 to 5.4.13 on August 14, 2026<\/strong>. The setup and directory permissions had not been changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This looks like a possible regression in version 5.4.13, potentially related to the CSRF\/security handling of write requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Could you please check whether this is a known issue with version 5.4.13?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thank you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Best regards,<br \/>Reiner<\/p>\n","protected":false},"template":"","class_list":["post-18994396","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18994396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18994396\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18994396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}