Ffile2fix
Sign in Get started

How to fix "Sorry, you are not allowed to upload this file type"

Sorry, you are not allowed to upload this file type.

WordPress only accepts uploads whose extension and detected MIME type appear on its allowed list. Files like SVG, JSON, WOFF2 or some CSVs are rejected either because the type is not allowed or because PHP's fileinfo detects a different MIME type than the extension suggests.

Also appears as: Sorry, this file type is not permitted for security reasons. · filename.svg: Sorry, you are not allowed to upload this file type. · This file cannot be processed by the web server.

Common causes

  • The extension is not on WordPress's default allow-list (SVG, JSON, fonts, EPS)
  • The file's real content type does not match its extension (e.g. a CSV detected as text/plain or application/octet-stream)
  • The user role lacks the unfiltered_upload capability
  • On Multisite, the extension is missing from Network Settings > Upload file types
  • A security plugin further restricts allowed upload types

How to fix it

  1. Confirm the file is what it claims. Open the file in a text editor or check it with the file command. A file renamed from another format will be rejected by WordPress's real-MIME check, which is correct behaviour.
  2. Add the MIME type with upload_mimes. In a small custom plugin or your child theme's functions.php, add only the extension you need to the upload_mimes filter, mapped to its correct MIME type.
  3. Handle mismatched MIME detection. If the type is allowed but still rejected, PHP fileinfo may report a different MIME. Map the extension to the MIME type that finfo actually reports, or use the wp_check_filetype_and_ext filter for that specific extension.
  4. Use a sanitizing plugin for SVG. SVG can contain JavaScript, so only allow it through a plugin that sanitizes SVG on upload, and restrict it to trusted roles.
  5. Update Multisite upload types. On Multisite go to Network Admin > Settings and add the extension to 'Upload file types'.
  6. Upload via SFTP when appropriate. For files that only need a URL (like a downloadable dataset), upload them over SFTP to a folder outside the media library instead of widening the allow-list.

custom plugin or child theme functions.php

add_filter( 'upload_mimes', function ( $mimes ) {
    if ( current_user_can( 'manage_options' ) ) {
        $mimes['json']  = 'application/json';
        $mimes['woff2'] = 'font/woff2';
    }
    return $mimes;
} );

How to stop it happening again

  • Allow only the specific extensions you need, never a blanket ALLOW_UNFILTERED_UPLOADS
  • Restrict risky types like SVG to administrators
  • Keep uploads scanned, since media folders are a common malware drop point

Frequently asked questions

Should I define ALLOW_UNFILTERED_UPLOADS?

Avoid it. It lets administrators upload any file type, including PHP files, which is a serious risk if an admin account is compromised. Allow only the extensions you need instead.

Why is my CSV rejected when CSV is allowed?

PHP fileinfo may detect the CSV as text/plain or application/octet-stream, which does not match WordPress's expected text/csv. Saving it as UTF-8 with consistent delimiters often fixes detection.

Is uploading SVG safe?

Only if it is sanitized. SVG is XML and can embed scripts that run when the file is opened directly, so use a sanitizing plugin and trusted uploaders only.