Skip to content
Conversion Wizard logoConversion Wizard

"Sorry, This File Type Is Not Permitted for Security Reasons"

WordPress refuses any upload outside its allow-list of file types. For images, the usual culprits are SVG, AVIF and HEIC — and converting is a better fix than switching the check off.

You drag an image into the WordPress media library and get “Sorry, this file type is not permitted for security reasons.” Note what this error is not saying: it isn’t about file size, and it’s not claiming your file is malicious. WordPress maintains a list of extensions it will accept, your file’s isn’t on it, and that’s the end of the conversation.

The “security reasons” phrasing is doing real work, though, and it’s worth understanding before you reach for the first fix the internet offers you.

Which image formats trigger it

  • SVG — blocked by default, always, on every WordPress install. This is the one case where the security wording is literal: an SVG is an XML document that can legitimately contain JavaScript, so an uploaded SVG is a potential cross-site-scripting vector. WordPress excludes it deliberately, not as an oversight.
  • AVIF — WordPress has supported AVIF uploads since version 6.5. On anything older, it’s rejected.
  • HEIC / HEIF — not on the allow-list. Photos straight from an iPhone hit this constantly.
  • WEBP — supported since WordPress 5.8. Only an issue on genuinely old installs.
  • Camera RAW (.cr2, .nef, .arw, .dng) — not permitted, and wouldn’t be much use in a web page anyway.

The same error also appears for fonts (.woff, .woff2, .ttf), .json files and anything else outside the list — a common surprise when installing a theme that expects you to upload its font files through the media library.

Your host can narrow the list further than WordPress core does, and some managed hosts do. If a format that should be allowed is being rejected, that’s worth asking them about.

The fix we’d recommend: convert the file

Search this error and the top result will usually tell you to add define('ALLOW_UNFILTERED_UPLOADS', true); to wp-config.php. That does work. We’d encourage you not to do it, and it’s worth being clear about why rather than just saying “use our tool.”

That constant doesn’t whitelist the one format you need. It disables the upload type check entirely, for every file type, site-wide, for anyone who can upload — including any contributor account, and including an attacker who gets hold of one. It is the single setting standing between a compromised login and someone uploading an executable PHP file into your web root. For the sake of posting one image, that is a poor trade.

Converting to JPG or PNG solves the immediate problem and leaves your site’s defences intact. For photographs, it’s also just better practice: JPG and PNG are what WordPress’s own image pipeline is built around, so thumbnails, responsive sizes and any optimisation plugin you use will all behave normally.

Convert it to a format WordPress accepts

HEIC, HEIF, AVIF, SVG and more → JPG or PNG. Runs in your browser; nothing is uploaded.

Convert to:

Drop your images here

or click to browse your device

Choose Files

Supports HEIC, JPG, PNG, WEBP, AVIF, GIF, BMP, SVG, PDF · up to 50 files · max 100 MB each

Your images never leave your device.

Pick JPG for photographs. Pick PNG for logos, icons and anything with flat colour or transparency — including SVGs, where PNG preserves the transparent background. Our guide to converting SVG to PNG explains how to choose an output resolution, since you’re turning something infinitely scalable into fixed pixels and that decision matters.

When you genuinely do need SVG

Sometimes a PNG won’t do — a logo that has to stay razor-sharp on every screen is a real case for SVG. If so, the right approach is a plugin such as Safe SVG, which permits SVG uploads and sanitises them, stripping scripts and event handlers before the file is stored. That is a far narrower and safer change than turning off all upload filtering.

If you only need the file once and don’t want a plugin at all, you can also upload it outside the media library — place it in your theme folder or a subdirectory over SFTP and reference it directly. Fine for a one-off; awkward to maintain.

If it’s a size error, not a type error

These two get conflated constantly. Check the exact wording:

  • “not permitted for security reasons” — wrong format. Convert it.
  • “exceeds the maximum upload size for this site” — the file is too big. That’s a server limit, and compressing the image is the fix. See our guide to compressing images for WordPress.

It’s entirely possible to hit both in sequence: convert a 6 MB HEIC to JPG, clear the type error, and immediately run into the size limit. If that happens, use the compressor on the converted file.

Frequently asked questions

Why does WordPress block SVG but not PNG?

Because a PNG is only pixel data — there is nothing in it a browser will execute. An SVG is markup, and it can carry <script> tags and event handlers that run when the image is viewed. The distinction is about executable content, not about how modern the format is.

Will converting to JPG hurt my site’s performance?

Not meaningfully. AVIF and WEBP are more efficient per byte, which is a real advantage, but a correctly sized and compressed JPG is perfectly fast — and many WordPress hosts and plugins now generate WEBP versions automatically from whatever you upload, so you may get the modern format served anyway without uploading one.

Can I add just one file type to the allow-list?

Yes, via the upload_mimes filter in your theme or a small plugin. That’s a reasonable middle ground: it permits exactly the type you want and leaves everything else blocked. It still won’t sanitise SVGs, so use Safe SVG for those rather than just permitting them.

Is converting here safe for client work?

The conversion happens in your browser and no image data is transmitted, so unreleased client assets don’t end up on a third-party server. You can verify that in your browser’s Network tab, and the source code is public if you want to read it.

Does this affect the WordPress block editor differently?

No. The block editor, the classic editor and the media library all go through the same upload validation, so the error and the fix are identical in each.

Ready to convert your HEIC photos?

Open the free converter and turn your HEIC or HEIF images into PNG files right in your browser.

Open the converter

Your images never leave your device

SYNTRX.DEVPowered by SYNTRX.DEV