How to fix "Sorry, you are not allowed to upload this file type" in WordPress
WordPress accepts a file only when its extension is on its list of allowed types and its content matches that extension. Save the file in a format on the list, or add the one type you need with a short plugin. Leave the check itself switched on.
- By
- WP Ministry
- Published
- Tested on
- WordPress 7.1.3, PHP 8.3.35
In short
- Nothing is lost or broken. WordPress refused one file, and the site is as it was.
- One message covers two refusals: the extension is not on the list, or the content is not what the extension says.
- A default install's list has no SVG, JSON, XML or font formats.
- Renaming a file changes its name only. WordPress reads the content too.
- A short plugin on the upload_mimes filter adds one type and leaves the check in place.
- ALLOW_UNFILTERED_UPLOADS adds no type. It ends the check for administrators, PHP files included.
WordPress puts every upload through two checks before it keeps the file. The extension has to be on its list of allowed types, and the content has to be what the extension says. "Sorry, you are not allowed to upload this file type." means the file failed one of the two. The message does not say which.
Nothing has been lost. WordPress refused that one file and changed nothing else, and other files upload as they did before.
The quickest way through is usually to save the file in a format that is on the list. Where the site really needs a type that is not, a few lines of code add that one type. Both are below, with the network setting that does the same job on multisite.
Where WordPress prints it
- Media, Add Media File. The file's name in quotation marks, "has failed to upload.", and the message under it.
- The Media Library and the media window of an editor. The message, with the file's name.
- The block editor. The file's name, a colon and the message, as in "logo.svg: Sorry, you are not allowed to upload this file type." The editor holds a copy of the list and refuses the file itself, before anything is sent.
- WP-CLI.
wp media importprints "Warning: Unable to import file", the path, and "Reason: Sorry, you are not allowed to upload this file type.", then "Error: No items imported." - The REST API. A request to
/wp/v2/mediais answered with status 500, the message, and the coderest_upload_sideload_error, orrest_upload_unknown_errorwhen the file was sent as a form. The 500 is how WordPress reports the refusal. Nothing on the server has failed.
WordPress 5.8 and earlier say "Sorry, this file type is not permitted for security reasons." for the same refusal. WordPress 5.9 changed the wording because security is not always the reason: the type may simply not be on the list.
"Sorry, this file type is not supported here." is a different message. The block editor prints it when a block takes only certain kinds of file and is given another, such as an Image block given a PDF. The file itself may be fine: add it with a File block, or through the Media Library.
A file that is too large, or an upload that fails on the server, gets a message of its own. See "The uploaded file exceeds the upload_max_filesize directive in php.ini", the "HTTP error" when uploading images and "Missing a temporary folder".
The two checks
The list. WordPress starts from a built-in list that pairs extensions with types: common image, audio, video, document and archive formats. It removes .swf and .exe for everyone, and .html and .js for any user who may not post unfiltered HTML. Plugins, themes and, on a network, WordPress itself can then change the list through a filter named upload_mimes. What is left is what you may upload.
A default install's list has no svg, json or xml, and no font format such as ttf, otf, woff or woff2.
The content. WordPress then looks inside the file.
- An image is identified from its own data. If it is a real image of another kind than its name says, WordPress does not refuse it. It corrects the extension, so a PNG named
photo.jpgis stored asphoto.png. - Any other file is identified by PHP's
fileinfoextension, and what that reports has to agree with the extension. There is some leeway for audio, video and a few text formats, and none for the rest.
The second check is why renaming a file does not get it through, and why some files fail with an extension that is on the list. A stylesheet is one: css is on the list, but a server may report a stylesheet as plain text, and WordPress accepts plain text only under a few extensions such as .txt and .csv.
Find out which check refused the file
With WP-CLI, this prints the list as it stands on your site for a user with no special rights:
wp eval 'echo implode( " ", array_keys( get_allowed_mime_types() ) ), PHP_EOL;'Extensions that share a type are joined with a bar, as in jpg|jpeg|jpe. If your file's extension is not there, the list refused it. If it is there, the content did.
This prints what the server makes of the content, with the path to your own file in place of path/to/file.json:
wp eval 'echo mime_content_type( "path/to/file.json" ), PHP_EOL;'For a JSON file it should print application/json. An answer such as text/plain or text/html for a file that is meant to be something else means the content is not what the name claims, or the server cannot tell.
If WP-CLI is new to you, How to use WP-CLI covers connecting over SSH. Without it, go by the extension: the lists above name the common types that are missing, and a file whose extension is a common one was most likely refused for its content.
Two shortcuts to leave alone
ALLOW_UNFILTERED_UPLOADS
A line that is often passed around, define( 'ALLOW_UNFILTERED_UPLOADS', true ); in wp-config.php, makes the message go away. It does not add a type to the list. It gives the unfiltered_upload capability to the users whose role holds it, and for them WordPress skips both checks. WordPress's documentation says no role has the capability unless the constant is defined, and that on a network only super admins can have it. On a default single site the role that holds it is Administrator.
With the line in place, an administrator's upload is not checked at all. A .php file is accepted like any other and saved in the uploads folder, where the web server will run it unless it has been set up not to. Anyone who gets hold of an administrator's password, or of an administrator's open session, can then put a program on the server through the upload form. If you find the line in a wp-config.php you have inherited, remove it and use the plugin above for the types the site needs.
SVG allowed with the filter alone
The same few lines with svg and image/svg+xml do make WordPress accept SVG files. They do nothing about what is inside them. An SVG file is a document, and it may carry scripts. Browsers switch those scripts off when the SVG is shown as an image in a page, and not when the file is opened at its own address. Every upload has an address of its own, so a script in an uploaded SVG runs in a visitor's browser as part of your site when someone follows a link to the file.
The filter adds a name to the list, and the content check only confirms that the file is an SVG. Neither reads the scripts. So an SVG needs to be cleaned as it is uploaded, by a plugin made for that. Safe SVG is one in the WordPress.org directory: its listing says it sanitizes each upload and can limit which users may upload SVG, and also that it cannot promise to cover every upload path other code may add. Where the picture only has to be shown, a PNG or WebP export avoids the question.
Where it goes wrong
A page request passes through each of these in turn. This one comes from WordPress itself.
- Browser
- DNS
- HTTPS
- CDN or firewall
- Web server
- PHP
- WordPress (this error comes from here)
- Database and files
What causes it
The file's type is not one WordPress accepts
CommonWordPress keeps a list of the extensions it accepts. On a default install that list has no svg, json or xml, and no font format such as woff2. A file with any other extension is refused whatever is in it.
Fix: Save the file in a format WordPress accepts, or Add one type to the list with a short plugin
The content is not what the extension says
CommonWordPress does not take the extension on trust. It identifies an image from the image's own data, and since version 4.7.1 it has the server identify every other file too. When the content and the extension disagree, the file is refused even though the extension is on the list. A text file named .pdf is one example.
Your role is not allowed that type
SometimesAn .html file is accepted only from a user who may post unfiltered HTML. On a single site that is an Administrator or an Editor, and on a network only a super admin. An Author is refused the file an Editor can upload.
The network's list of upload types leaves it out
SometimesOn a multisite network, WordPress cuts the list down to the extensions in the network setting "Upload file types". A type that is missing there is refused on every site of the network.
A plugin or the theme has taken the type off the list
RareThe filter that adds a type to the list can remove one as well. Code in a plugin or a theme that does so makes WordPress refuse a type it accepted before.
Fix: Find the plugin or theme that took the type off the list
How to fix it
Save the file in a format WordPress accepts
- Easy
- No risk
- About 10 minutes
This changes nothing on the site, so try it first.
Step 1: If the extension is on the list, export the file again
Open the file in the program that made it and use its export or "Save as" command to write the format the name claims. Typing a new extension over the old one changes the name and nothing else, and WordPress reads the content.
Step 2: If the type is not on the list, use one that is
Export a logo or an icon drawn as SVG to PNG or WebP. How to optimize WordPress images without losing quality covers choosing between formats. Save data as CSV where the program offers it.
Step 3: If visitors only need to download the file, zip it
A
.zipfile is on the list. A font, a JSON file or a set of documents inside one uploads as an archive, and visitors get the original when they unpack it.Step 4: If the file is an .html page and you are an Author
Ask an Editor or an Administrator of the site to upload it, or zip it.
To undo it: There is nothing to undo. The site is not changed.
Add one type to the list with a short plugin
- Takes care
- Low risk
- About 10 minutes
- Steps tested on WordPress 7.1.3
When the site needs a type that is not on the list, add that type and no other. The example adds JSON.
Step 1: Create the mu-plugins folder if it is not there
Look in
wp-content. If there is no folder namedmu-plugins, create one in the host's file manager or over SFTP. WordPress loads every PHP file in that folder as a must-use plugin. Over SSH, from the folder WordPress is installed in:bashmkdir -p wp-content/mu-pluginsStep 2: Add the file
Save this as
allow-json-uploads.phpin that folder.wp-content/mu-plugins/allow-json-uploads.php<?php /** * Plugin Name: Allow JSON uploads * Description: Adds .json to the file types WordPress accepts as uploads. */ add_filter( 'upload_mimes', function ( $types ) { $types['json'] = 'application/json'; return $types; } );Step 3: Upload the file again
Use Media, Add Media File as before. With WP-CLI, give the path to your own file:
WP-CLI answers "Success: Imported 1 of 1 items."
bashwp media import path/to/file.json
The type is now allowed for every user who may upload files, which on a default install is Authors, Editors and Administrators.
The content check still applies. If the file is refused although its extension is now on the list, run the second command under "Find out which check refused the file". The type in the plugin has to be the one the server reports. A file named .json that holds something other than JSON is still refused, as it should be.
If you cannot create the folder or save the file, the account you are signed in with may not write there. WordPress file permissions explains who should own the files and what to ask your host.
To undo it: Delete the file from wp-content/mu-plugins. Files uploaded in the meantime stay in the Media Library.
Find the plugin or theme that took the type off the list
- Takes care
- Low risk
- About 15 minutes
- Steps tested on WordPress 7.1.3
If a type WordPress accepts by default, such as PDF, is refused, and the content is what the name says, something has removed it from the list.
Print the list twice, once as the site runs and once with plugins and the theme left out:
wp eval 'echo implode( " ", array_keys( get_allowed_mime_types() ) ), PHP_EOL;' --skip-plugins --skip-themesCompare it with what the first command on this page printed. If the type is in this list and not in that one, a plugin or the theme is removing it. Switch plugins off one at a time, with each plugin's name in place of plugin-slug, and try the upload after each:
wp plugin deactivate plugin-slugWhen the upload goes through, the last plugin you switched off is the one. Look in its settings for a list of allowed file types before deciding to do without it. Without WP-CLI, How to find and fix a WordPress plugin conflict does the same from the dashboard.
--skip-plugins does not skip must-use plugins. If both lists lack the type, look through the files in wp-content/mu-plugins, and on a network use the next fix.
To undo it: Activate the plugin again on the Plugins screen.
On a network, add the type to Upload file types
- Easy
- Low risk
- About 5 minutes
- Steps tested on WordPress 7.1.3
A multisite network has a list of its own, and only a super admin can change it.
Step 1: Open the network's settings
In the Network Admin, open Settings, then Network Settings, and scroll to "Upload Settings".
Step 2: Add the extension to "Upload file types"
The field holds extensions separated by spaces. Add the one you need, without a dot, and click Save Changes.
With WP-CLI, this prints the setting:
wp site option get upload_filetypesAnd this adds one extension to the end of it, with yours in place of pdf:
wp site option update upload_filetypes "$(wp site option get upload_filetypes) pdf"The setting can only narrow what WordPress accepts. Typing json or svg into the field does not make WordPress accept it, because the type has to be on WordPress's own list first. A type added with the plugin above is accepted on every site of the network, whatever this field holds, because WordPress applies the setting before the plugin adds its type.
To undo it: Take the extension out of the field again and save.
When to get help
If a type that should be accepted is still refused after these steps, either the server identifies the file's content as something unexpected, or code you have not found is changing the list. Telling the two apart means reading both on the server itself, and that takes shell access.
Common questions
I renamed the file and WordPress still refuses it. Why?
Because WordPress looks at the content as well as the name. A new extension does not change what is in the file. Export it from the program that made it in the format you want, or add the file's real type to the list.
Does the message mean my site has a security problem?
No. Older versions of WordPress said the file was "not permitted for security reasons", which read like a warning about the site. It is a rule applied to one file. The site has not been attacked, and nothing on it has changed.
Is the file too big?
Not if you see this message. A file over the size limit is told it "exceeds the maximum upload size for this site." or names PHP's upload_max_filesize, and that page shows how to raise the limit.
Will the type I added survive updates?
Yes. A file in wp-content/mu-plugins belongs to neither WordPress nor the theme, and updates to either leave it alone. It also stays when you change themes, which code in a theme's functions.php would not.

