"Sorry, You Are Not Allowed to Upload This File Type" in WordPress
WordPress rejects a file with "Sorry, you are not allowed to upload this file type" or "Sorry, this file type is not permitted for security reasons" — it does not recognise the file as one of its allowed types.
Common signs of this issue
- WordPress shows "Sorry, you are not allowed to upload this file type" when you add a file to the media library.
- Older sites show the wording "Sorry, this file type is not permitted for security reasons" instead.
- The problem file is usually an SVG logo, a font file, a ZIP, a design file, a spreadsheet in an unusual format, or an iPhone photo.
- The same file uploads fine on another WordPress site, or used to upload fine on this one.
- A file you renamed — for example from .webp to .jpg — is rejected even though it opens on your computer.
- An editor or author gets the error while an administrator can upload the same file.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Look at the file's real extension. On Windows, turn on File name extensions in File Explorer's View menu; on a Mac, use Get Info. A file called logo.svg or font.woff2 is a type WordPress does not allow by default, which explains the message immediately.
- Check whether the file is a common type that should work: JPG, PNG, GIF, WebP, PDF, Word, Excel, PowerPoint, MP3, and MP4 are all allowed in normal WordPress. If one of those is being rejected, the file may be misnamed, damaged, or your site may have a plugin restricting uploads.
- If the file was renamed, re-save or export it properly instead. WordPress checks the actual contents of the file, not just the name, so an image converted by renaming will be refused. Open it in an image editor and export it as a real JPG or PNG.
- Check your WordPress version under Dashboard, then Updates. WebP support arrived in version 5.8 and AVIF in 6.5. An old site will reject modern image formats that newer versions accept — updating (safely, with a backup first) may be the whole fix.
- For an SVG logo, the simplest option is often to export a PNG version from the designer's file. If you really need SVG, use a well-maintained plugin that sanitises SVG files on upload and ideally limits SVG uploads to administrators.
- For fonts, check whether your theme or page builder has its own font upload screen, or, on a block theme, the Font Library in the Site Editor. Those handle font files properly without opening up the general media library.
- If only some users get the error, look at their role under Users. Some roles and security plugins limit what non-administrators can upload. On a multisite network, the allowed types are also set in the network's settings.
- Check any security plugin you run for an upload or file-type setting. Some block additional types on top of WordPress's own list.
What this usually means
WordPress keeps a list of file types it will accept, and it checks both the file name's extension and what the file actually contains. Anything not on the list is rejected with this message. That is deliberate: a website that accepts any file will eventually accept a disguised script, and one malicious upload can hand an attacker the whole site. The error is WordPress doing its job, not a malfunction.
The files most often caught are SVG images, which can contain code as well as shapes, so WordPress does not allow them by default; font files like WOFF2 and TTF, which normally belong in a theme or font manager rather than the media library; modern image formats such as WebP or AVIF on an out-of-date WordPress; and files whose name does not match their contents, such as a renamed image or a file saved by an app that adds the wrong extension. A plugin or careful WordPress update fixes most of these cleanly.
The dangerous fix is the one many forum posts suggest: turning off the check entirely with a line in wp-config.php, or a plugin that lets every user upload any type. That removes the safety net for the whole site, for every account, forever — including any account whose password is later stolen. The right approach is to allow only the specific type you need, only for the people who need it, and, for SVG, only with sanitisation. If the file is simply too large rather than the wrong type, see upload_max_filesize exceeded; if the media library itself will not load, see media library not loading.
What not to do
- Don't add ALLOW_UNFILTERED_UPLOADS to wp-config.php to make the error go away. It disables the file-type safety check for administrators across the whole site.
- Don't install a plugin that allows every file type for every user. Allow only the specific type you need.
- Don't upload SVG files from unknown sources, even with a plugin installed. An SVG can carry hidden code.
- Don't rename a file's extension to sneak it past the check. WordPress inspects the contents, and a mismatched file can break in browsers even if it gets through.
- Don't give editors or authors extra upload powers just to save a few minutes. Keep broad upload rights with trusted administrators.
- Don't leave a temporary "allow all" setting in place after the upload is done. Temporary fixes have a way of becoming permanent.
When to get help
If a normal file type like a JPG or PDF is being rejected, if the error started after an update or a new security plugin, or if you need a specific type allowed and are not sure how to do it without weakening the site, it is worth having someone look. The fix is usually small — a sanitising plugin configured properly, a correct file type rule in a small custom plugin, or a WordPress update — but the wrong fix quietly opens a security hole that nobody notices until the site is compromised. An expert also checks whether the rejection is hiding a different problem, such as a damaged file or a misbehaving plugin.
Glenn, who runs WebsiteSelfHelp, fixes WordPress upload problems for small businesses in a way that keeps the site safe. Tell him which file you are trying to upload and what the message says, and he will give you a plain answer on the safest way to get it working. Nothing needs to be handed over to begin.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does "Sorry, you are not allowed to upload this file type" mean?
WordPress does not have the file's type on its list of allowed uploads, or the file's contents do not match its name. It is a security check, not a fault with your site.
Why can't I upload SVG files to WordPress?
SVG files can contain code as well as images, so WordPress blocks them by default. You can allow them with a reputable plugin that sanitises SVG files on upload, ideally limited to administrators, or use a PNG version instead.
Does WordPress support WebP and AVIF images?
Yes, in current versions. WebP has been supported since WordPress 5.8 and AVIF since 6.5, as long as your server's image library supports them. On older WordPress versions, those files are rejected.
Is it safe to allow all file types in WordPress?
No. Turning off the check removes an important protection against malicious uploads. Allow only the specific types you need, for the users who need them.
Why can an administrator upload a file but an editor cannot?
WordPress and some security plugins give different roles different upload rights. Administrators on single sites have broader permissions than editors and authors, which is intentional.
How do I upload font files to WordPress?
Use your theme's or page builder's font upload option, or the Font Library in the Site Editor if you use a block theme. Those tools are built for fonts and avoid opening up the general media library.
Can I fix the file type not permitted error myself?
Often. Exporting the file in a normal format, updating WordPress, or installing a reputable plugin for one specific type fixes most cases. Get help if a normal file type is rejected or you are unsure the fix is safe.