WordPress

Fix: WordPress Update Failed – cURL Error 60: SSL Certificate Problem

If you see this error when updating WordPress plugins or themes, this guide will help you fix it:

Update Failed: Download failed. cURL error 60: SSL certificate problem: unable to get local issuer certificate

What you’ll do: Replace an outdated SSL certificate file in WordPress using cPanel File Manager. Takes about 5 minutes, no technical experience needed.


Quick Navigation


What Causes This Error?

When WordPress updates plugins or themes, it downloads files from WordPress.org using a secure SSL connection. To verify the connection is safe, WordPress checks the server’s SSL certificate against a trusted list stored in ca-bundle.crt.

The cURL error 60 means WordPress doesn’t recognise the certificate authority that issued WordPress.org’s certificate. This happens on older WordPress installations where the ca-bundle.crt file is outdated.

The fix: Replace the old certificate bundle with the latest version—or update WordPress itself, which does this automatically.


Alternative: Update WordPress Using WordPress Manager

If your WordPress core is outdated, the easiest fix is to update WordPress itself. This automatically replaces the outdated certificate file.

Use Ecenica WordPress Manager to update safely:

  1. Log in to your Ecenica Dashboard
  2. Click Manage next to your hosting service
  3. Click WordPress Manager
  4. Find your WordPress site and click Update if available

WordPress Manager handles the update safely and replaces outdated files automatically.

Full guide: How to Upgrade WordPress via WordPress Manager

If you can’t update WordPress (or still see the error after updating), follow the manual fix below.


Manual Fix: Step-by-Step

If updating WordPress doesn’t resolve the issue, or you need to keep your current WordPress version, follow these steps to replace the certificate file manually.

Before You Start

You’ll need:


Step 1: Download the New Certificate File

  1. Download the latest certificate bundle from WordPress:

    Download ca-bundle.crt

  2. Your browser will display the file contents. Right-click and select Save As

  3. Save to your Downloads folder

Important: The filename must be exactly ca-bundle.crt. Some browsers add .txt to the end. If this happens, rename the file and remove .txt.


Step 2: Open File Manager for your Ecenica web hosting service

  1. Log in to Ecenica Dashboard
  2. Click Services > My Services.
  3. Click Manage next to your Ecenica web hosting service.
  4. Click File Manager.

File Manager will open in a new browser tab showing your web hosting files.


Step 3: Find the Certificates Folder

Navigate to:

public_html/wp-includes/certificates

WordPress in a subfolder? Adjust the path:

subfolder/wp-includes/certificates

Step 4: Backup the Old Certificate File

Before replacing the file, rename the old one as a backup.

  1. Find ca-bundle.crt
  2. Right-click and select Rename
  3. Add bak: ca-bundle.crt.bak
  4. Click Rename File

If anything goes wrong, you can restore this backup by renaming it back to ca-bundle.crt.


Step 5: Upload the New Certificate File

  1. Ensure you’re in the /certificates folder
  2. Click Upload
  3. Click Select File and choose the ca-bundle.crt you downloaded in Step 1
  4. Wait for upload to complete
  5. Click the back arrow to return to /certificates
  6. Confirm the new ca-bundle.crt appears in the file list

Step 6: Test Your WordPress Updates

  1. Log in to your WordPress Dashboard
  2. Go to Dashboard > Updates
  3. Try updating a plugin or theme

The cURL error 60 should no longer appear.


You’re Done!

Your WordPress site can now securely download updates from WordPress.org. The error is fixed.

Still seeing issues? See Troubleshooting below.


Troubleshooting

The Error Still Appears

Check:

  • File is named exactly ca-bundle.crt (not ca-bundle.crt.txt)
  • File is in /wp-includes/certificates/
  • Permissions are set to 644

I Don’t Have a Certificates Folder

Your WordPress installation may be damaged or non-standard. Contact Ecenica support for help.

I’m Not Sure Where WordPress is Installed

If you used Ecenica WordPress Manager, your site is likely in public_html. Check for a wp-includes directory in File Manager.

I Deleted the Old File Without Backing It Up

Download the file from the GitHub link in Step 1 and upload it. The file is the same for all WordPress installations.

File Manager Won’t Let Me Upload

Check your storage space. If full, delete unnecessary files or upgrade your plan.

Updates Still Fail After Replacing the File

Your WordPress version may be significantly outdated. Try updating WordPress using WordPress Manager (see Alternative: Update WordPress above).

If you’re unsure how to proceed, contact Ecenica support.


Frequently Asked Questions

Will this affect my live website?
No. You’re updating a file WordPress uses internally. Your site continues working normally.

Do I need to do this for every WordPress site?
Yes, if each site shows the error. Each WordPress installation has its own certificate file.

Is it safe to delete the backup file?
Yes, once updates work. Delete the renamed backup (e.g., ca-bundle.crt.20250321) after confirming everything works.

How often does this file need updating?
Rarely. Updating WordPress core refreshes this file automatically. Manual replacement is only needed when WordPress is outdated.


Need Help?

If you’re experiencing issues or need assistance, contact Ecenica support.

Was this guide helpful?

Need help with this?

Open a ticket and link to this guide so our team can see what you have tried.

View support tickets

Power your business with Ecenica Hosting

Built for WordPress and serious websites. Fast, secure and supported by real people in the UK.

Ecenica hosting services represented by a connected red route across London