WordPress

How to Fix “Sorry, This File Type is Not Permitted for Security Reasons” in WordPress

If you’re trying to upload a file to your WordPress site and encounter the error:

“Sorry, this file type is not permitted for security reasons,”

This error message means WordPress is blocking the file type for security reasons. By default, WordPress restricts certain file types to prevent potential security risks, but this error can be fixed in several ways depending on your needs.

Why Does WordPress Block Certain File Types?

WordPress only allows common file types like images, documents, and media to be uploaded. Some of the supported formats include:

  • Images: .jpg, .jpeg, .png, .gif
  • Documents: .pdf, .doc, .ppt
  • Audio/Video: .mp3, .mp4, .mov

When trying to upload a less common file type, like .svg, .json, or .eps, WordPress will block it for security reasons.

Ways to Fix the “File Type Not Permitted” Error

There are several ways to fix this error and enable additional file types in WordPress. Here’s how:

Solution 1: Use a Plugin to Enable Additional File Types

The easiest method is to use a plugin to allow extra file types without manually editing any code.

  1. In your WordPress dashboard, navigate to Plugins > Add New.
  2. Search for a plugin like WP Extra File Types or File Upload Types by WPForms.
  3. Click Install and then Activate.
  4. Once activated, go to Settings > Extra File Types.
  5. Check the box next to the file types you want to enable (e.g., .svg, .json).
  6. Click Save Changes.

After this, you should be able to upload the additional file types without encountering the error.

Solution 2: Add Allowed File Types in the ‘functions.php’ File

If you want more control, you can manually add specific file types by editing your theme’s functions.php file.

Steps:

  1. Access the functions.php File
    • Access your functions.php file via SFTP, FTP or File Manager on your Ecenica hosting service.
    • Alternatively, you can open functions.php from Appearance > Theme Editor in your WordPress dashboard. Then open the functions.php file from the list of theme files on the right.
  2. Add Custom MIME Types
    Add the following code to the file to enable specific file types (for example, .svg and .json):

       function custom_mime_types($mimes) {
           $mimes['svg'] = 'image/svg+xml';
           $mimes['json'] = 'application/json';
           // Add more file types if needed
           return $mimes;
       }
       add_filter('upload_mimes', 'custom_mime_types');
       
  3. Save the File
    Click Update File to save the changes or save and upload your file if you are using FTP, SFTP or File Manager. You should now be able to upload the specified file types in your WordPress Dashboard.

Solution 3: Enable All File Types via the ‘wp-config.php’ File (Caution)

If you need to allow uploads of all file types (though this is not recommended for security reasons), you can modify the ‘wp-config.php’ file.

Steps:

  1. Access the wp-config.php File
    Use an FTP client or your Ecenica hosting File Manager to access the WordPress root directory and open the wp-config.php file.
  • Add Code to Allow All File Types
    Add the following line of code right before the line that says /* That's all, stop editing! Happy blogging. */:

    define('ALLOW_UNFILTERED_UPLOADS', true);
    

  • Save and upload the updated wp-config.php file.
  • This method removes all file type restrictions, so we do not recommend it over the other solutions. Use it cautiously to avoid security vulnerabilities.

    Was this guide helpful?

    Need help with this?

    Open a ticket and link to this guide so our team can see what you have tried.

    View support tickets

    Power your business with Ecenica Hosting

    Built for WordPress and serious websites. Fast, secure and supported by real people in the UK.

    Ecenica hosting services represented by a connected red route across London