Open WordPress → Tools → Site Health and record the exact failing test. A REST API failure and a loopback failure are diagnostic results, not proof of a single cause.
Loopback requests let WordPress call its own site and are used for tasks such as scheduled events and checks around built-in code editing. Active PHP sessions can interfere with REST API and loopback requests.
- Note the error, time, and recent plugin, theme, URL, or access-control changes.
- Check the configured site address and HTTPS behavior for unexpected redirects or certificate errors.
- Use a staging copy to test suspected plugin or theme conflicts one change at a time. Keep a backup and record how to reverse each change.
- Review relevant error logs privately. If a security rule or authentication layer is involved, test narrowly; do not broadly disable protection on the public site.
- Repeat the same Site Health test and restore any diagnostic changes that did not help.
Do not hide the warning or disable the REST API as a substitute for investigating the reported failure.
Reference: WordPress Site Health.