Upload SVG Files Without Removing WordPress Safeguards
- SVG is useful because it can remain sharp at any resolution and often produces small files for logos, icons, diagrams, and interface graphics. However, SVG is not simply an image container. It is an XML document capable of containing scripting, event handlers, embedded objects, external references, and other features that can become unsafe when arbitrary uploads are served by the website.
- WordPress blocks SVG uploads by default for that reason. SVG Upload provides a more controlled path instead of merely adding image/svg+xml to the allowed MIME list. Only administrators can use the capability, and the uploaded document is parsed and rewritten after sanitization before it becomes a normal Media Library attachment.
Sanitize the SVG Before It Is Stored
- WP PowerSuite requires the file to parse as XML and requires the document root to be an actual
- The sanitizer removes dangerous elements such as script, foreignObject, embed, object, iframe, handler, base, and import. It also strips attributes beginning with on, such as onclick or onload, and rejects unsafe javascript:, data:, and vbscript: references in relevant URL-bearing attributes.
Style blocks containing @import or legacy expression() behavior are removed, and <use> references are limited so local fragment references such as #icon can remain while external or executable targets are rejected.
Handle SVGZ as Real Compressed SVG
- An SVGZ file is a gzipped SVG document, so validation cannot stop at the compressed bytes. WP PowerSuite detects gzip content, decompresses it, runs the same XML and sanitization checks against the decoded SVG, and then compresses the cleaned result again.
- This provides a consistent policy between .svg and .svgz rather than allowing the compressed variant to bypass protections that only inspect plain XML.
Keep SVG Uploads Restricted to Administrators
- SVG sanitization reduces risk but cannot guarantee that every future browser behavior or exotic SVG construction is harmless. WP PowerSuite therefore combines sanitization with a strict capability boundary.
- Only users with manage_options receive the SVG MIME type and are allowed through the upload prefilter. REST uploads from unauthorized users receive a 403 response. Editors and authors cannot upload SVG merely because they have ordinary upload_files permission.
- This policy is intentionally more restrictive than normal image uploads because SVG has a broader attack surface than JPEG or PNG.
Use SVG Naturally in the Media Library
- Once an SVG passes validation, WP PowerSuite corrects filetype detection so WordPress recognizes it as image/svg+xml and adds a full-size entry to Media Library attachment data when needed for previews.
- Intermediate image sizes are disabled for SVG because creating raster thumbnail derivatives would defeat much of the value of a scalable vector source and can produce inconsistent behavior across hosts. The original vector remains the attachment used by WordPress.
Understand the Limits of SVG Sanitization
- The module removes a defined set of dangerous tags, attributes, and URL schemes, but it does not claim to eliminate every theoretical XSS vector in the SVG specification. Complex inline CSS URLs, unusual namespaces, or future browser behaviors can create edge cases beyond a simple sanitizer.
- For highly sensitive environments, treat SVG as active content and consider whether serving user-supplied SVG is appropriate at all. The strongest use case for this module is trusted administrators uploading known branding and design assets rather than opening arbitrary vector uploads to every contributor.



