Common causes
- The server cannot resolve or reach its own domain (DNS points elsewhere, NAT, or firewall)
- A security plugin, WAF or Cloudflare rule blocking requests from the server IP
- Basic authentication (htpasswd) on a staging site blocking the request
- Incomplete SSL certificate chain or outdated CA bundle on the server
- A slow plugin or long PHP session lock making the request exceed the timeout
- session_start() in a plugin keeping the session locked during the request
How to fix it
- Test from the server itself. SSH into the server and run curl -I https://example.com/wp-cron.php. A timeout, connection refusal or SSL error here is the same problem WordPress sees.
- Fix DNS or hosts entries. If the domain resolves to a different IP from the server, add the correct internal IP to /etc/hosts, or fix the DNS record. Behind NAT the server may need its private IP.
- Allow the server's own IP. Whitelist the server IP in your security plugin, ModSecurity, fail2ban or Cloudflare firewall rules, and exclude wp-cron.php and /wp-json/ from rate limits.
- Repair the SSL chain. If curl shows error 60, install the full certificate chain (fullchain.pem) in the web server and update the system CA bundle (ca-certificates package).
- Find a slow or session-locking plugin. Use the Health Check & Troubleshooting plugin's troubleshooting mode or deactivate plugins one at a time. Plugins that call session_start() without closing the session commonly cause cURL error 28.
- Allow loopbacks on protected staging sites. If the site uses basic auth, allow the server IP in the auth rules, for example with Require ip in Apache, so internal requests are not blocked.
Test the loopback from the server
curl -sS -o /dev/null -w '%{http_code} %{time_total}s\n' https://example.com/wp-cron.php
curl -sS -I https://example.com/wp-json/
getent hosts example.com How to stop it happening again
- Whitelist the server's own IP in firewalls and security plugins
- Install the full SSL certificate chain
- Avoid plugins that hold PHP sessions open
- Check Tools > Site Health after server or DNS changes