.doc
files can contain executable scripts, and there is no way to make sure they are safe. The same applies to SVG and some other file types.
If WordPress would accept .doc
files from any user with the capability upload_files
, these files could be used to send malicious code to visitors.
Related Posts:
- simple solution for restricting access to (some) uploads/downloads
- Protecting direct access to PDF and ZIP unless user logged in (without plugin)
- What permissions does wp-content/uploads need?
- can not upload file .vtt on wordpress 5.0.1
- Password protect some uploaded files, so only logged-in users can view them
- How to protect uploads in multisite if user is not logged in?
- File Upload Permissions
- Extend the list of MIME-types supported by the builtin uploader in 3.3
- How to safely allow user upload on CPTs?
- making media URL secured
- Is it safe to allow non-admin users access to media uploader
- Is it safe to upload JSON files to upload folder?
- Setting up a HIPAA secured form / file upload
- Where to store sensitive uploaded file?
- WP upload/select image , isn’t this a security issue?
- What is the best way to upload a temporary & sensitive file and then delete it when done
- Basic File/Post restriction plugin
- Auto shortlink for file uploads
- How to parse an image that was just uploaded to make sure it doesn’t contain malicious code?
- How to Protect Uploads, if User is not Logged In?
- Plupload Intergration in a meta-box?
- Trigger refresh for new media manager in 3.5
- Physical organization of wordpress media library (Real Media Library plugin)
- Can I upload media to a specific folder?
- wp_upload_dir how to get just the directory name .
- How to generate thumbnails when needed only?
- Limit image upload to one and disable audio, video and other document file types to upload
- How to add new tab to media upload manager with custom set of images?
- No Thumbnails Generated
- Media files exist in upload folder but not showing up
- How to Require a Minimum Image Dimension for Uploading?
- How to upload files straight to S3 without using local storage? [closed]
- Extend Media Library
- How does WP media uploader create the 3 different sized images, and how can I duplicate it
- How to make “Upload files”selected by default in Insert Media?
- WordPress 3.5: Setting custom “full URL path to files” in the Media Library?
- Get $image_id after uploading with media_sideload_image()
- what happens to existing media files when I switch to year/month directory structure format?
- Reject upload of wrong-sized images using the Media Uploader
- WordPress Media Uploader events
- How to show all available images in WP’s media library when using the Polylang plugin?
- how to upload and allow downloads of .mobi and .epub formats
- Upload post thumbnail from the front end
- Allowing WebP uploads?
- Give users a maximum upload capacity; limit the number of files a user can upload OR limit the number of files per upload
- How to add a custom field to the media screen (image/gallery)?
- Can’t upload media, permissions are correct
- How to assign multiple file-mime-types to extension?
- Saving Media – Which Hook is Fired?
- Set limit to media upload?
- Is it possible to reorganize the WordPress uploads directory?
- Handling front-end file uploads, considering safety and ease of use
- WordPress 3.5: Switch back to Old Media Uploader?
- Save camera info as metadata on image upload?
- Media upload finished hook
- Users can’t upload images on frontend if they haven’t got access to the wp backend
- How to upload SVG in WordPress 4.9.8?
- How Can I Organize the Uploads Folder by Slug (or ID, or FileType, or Author)?
- How can I batch delete all unattached images with WP-CLI or other automated process?
- Can upload doc and pdf but not ppt – not permitted for security reasons
- Create image formats with different qualities when uploading
- Rename files during upload using variables
- upload_async.php returns 500 error
- Which filters or actions to use after a media upload and delete?
- Organize uploads by year, month and day
- wp_delete_attachment doesn’t delete images in wp-content/uploads/
- Display attachments by ID in a wp.media frame
- Force WordPress 3.3 to use Flash uploader
- Use a separate custom table (not posts) to handle file upload data
- Upload folder is not writable, even when permissions are correct
- Different upload directory based on post type in a theme
- Media not actually deleted on disk when click “Permanent Delete”
- Image upload callback in new 3.5 media
- retrieve custom image sizes from media uploader javascript object
- Add inline uploader to plugin option page
- How to wp_upload_bits() to a sub-folder?
- Using same directory for storing all uploaded images on a WordPress network
- Insert images to post not working
- Is it possible to allow zip files to be uploaded in WordPress?
- How to restrict images in v3.5 Media Library modal to only those from a specific post id?
- Allow CSV files to be uploaded
- Contact Form 7 – process form using a PHP script, instead of mailing [closed]
- Get an uploaded attachments local server path?
- How to add more upload directories?
- Change WordPress upload path and URL
- Could a large quantity of files in the uploads folder affect performance?
- PNG with transparent background turns black when uploaded and resized
- “Add Media” only shows “Full Size” under Attachment Display Settings
- Differentiate Featured Image from Post Images upon Upload
- WP 3.3 > Still no option to enable automatic image overwrites?
- Where do the favicons for Media Files come from
- How are the year and month folders added to the uploads directory?
- Where does wordpress store the FTP credentials?
- WP 3.5 media manager – how to create a working gallery frame
- Custom upload directory per CPT; when removed, file not deleted
- What might cause a POST to wp-admin/async-upload.php to return JSON >and< HTML?
- How to manage a standalone media folder?
- Send attachments via wp_mail from temporary folder
- Modify featured image path to Amazon S3
- wp_generate_attachment_metadata returns empty array