Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

An upload succeeds only when every limit on its request path accepts it. On shared hosting that path can include a PHP per-file cap, a PHP whole-request cap, a web-server or proxy body limit, time and memory limits, temporary storage, and your account’s disk quota. Raising upload_max_filesize changes only one of these layers, so a higher value often leaves the failure in place. The fix starts with finding which layer rejects the file, and only then changing the setting that controls it.

The layers an upload has to clear

Each layer has its own setting, its own error, and usually its own owner. The table lists them in the order a request meets them, from the outermost server down to storage.

Layer Control What it limits Who usually changes it
Web server or reverse proxy Nginx client_max_body_size; Apache LimitRequestBody Total size of the request body, before PHP handles it. An oversized Nginx request returns HTTP 413. Host or server administrator. Apache settings can sometimes be placed in .htaccess, but only if the server configuration permits it.
PHP per file upload_max_filesize Size of one uploaded file. Account holder where the control panel exposes it; otherwise the host.
PHP whole request post_max_size Complete POST body, including the file, multipart encoding, and other form fields. Same as above.
PHP memory and time memory_limit, max_execution_time, max_input_time Memory and run time while the upload is received and processed. Account holder within the limits the host allows.
Temporary storage upload_tmp_dir Where PHP stages the file before the application moves it. Usually the host; not stated for every plan.
Account quota Disk quota in the control panel Space left in the account after the file is stored. Account holder, within the plan’s quota.

Why raising upload_max_filesize alone fails

post_max_size covers the whole request

upload_max_filesize limits one file. post_max_size limits the complete POST body, which must hold that file plus multipart encoding and every other field in the form. If the file is close to the per-file cap, a low post_max_size rejects it anyway. WordPress’s PHP optimization handbook states that post_max_size should be greater than or equal to upload_max_filesize. The PHP manual documents these as core php.ini directives, but the values a host actually deploys can differ from the manual’s defaults, so the values you see in your control panel are the ones that count.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A web-server cap sits above PHP

A higher PHP value cannot override a cap enforced earlier in the request. Nginx documents the rule directly: “If the size in a request exceeds the configured value, the 413 (Request Entity Too Large) error is returned to the client.” That response comes from the server, so it can appear even when PHP settings look generous. Apache’s LimitRequestBody restricts total request-body size and can be set in server, virtual-host, directory, or .htaccess contexts, subject to the server’s configuration and permissions. Apache changed the default for this directive in version 2.4.54, so confirm the installed version and the active configuration rather than relying on a documented default.

Time and memory can fail after the bytes fit

A request can satisfy both size limits and still fail. A transfer that runs for a long time and then stops points toward max_execution_time or max_input_time, or toward a resource limit. memory_limit governs processing, and raising it to match the file size is not automatically correct. WordPress recommends coordinating these timeouts and contacting the host when shared-hosting limits cannot be changed.

Match the symptom to the layer

Error wording alone is an unreliable guide, but the pattern of failure is useful. Use this table to choose the first thing to check.

Symptom Likely layer First check
Rejected immediately with a size message; the same cutoff appears on every attempt PHP per-file or whole-request cap Values in MultiPHP INI Editor for the PHP version serving the site
HTTP 413 “Request Entity Too Large” response Web server or proxy body limit Whether the host can raise the body limit; changing PHP values will not help
Fails at the same size after PHP values are raised Upstream cap, security layer, or host policy Ask the host which layer rejects the request
Transfer runs for a long time, then fails Time limit or resource limit max_execution_time, max_input_time, memory_limit, and host limits
File Manager fails while website uploads of a similar size work File Manager HTTP submission size or account quota File Manager’s settings and remaining disk quota
The file is accepted but a later processing step fails Memory or time limits during processing memory_limit and time settings for the active PHP version

Fixing it step by step

Step 1: Confirm which upload path is failing

Separate uploads made by WordPress or another PHP application from uploads made through cPanel File Manager. They can be governed by different limits. Record the exact error text, the file size, the time of the attempt with its time zone, and whether the failure is immediate or comes after a long transfer. An immediate failure usually points to a cap. A failure after a long transfer points to a timeout or resource limit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 2: Read the effective values

Start by reading what the server actually applies to the site:

  1. Log in to cPanel and open MultiPHP INI Editor.
  2. Select the domain or PHP version that serves the site. Confirm it is the configuration in use, because a value set for another PHP version does nothing for this site.
  3. Record upload_max_filesize, post_max_size, memory_limit, max_execution_time, and max_input_time.
  4. In WordPress, open the upload screen under Media to see the maximum upload size it reports, and open Tools > Site Health and its Info tab to see the PHP values the site reads.

cPanel’s PHP upload-limit support article, dated April 11, 2026, describes a 2 MB default. That is cPanel’s documented default for the configurations it describes, not a standard for every shared host. Your account may differ.

cPanel’s documentation also states that the MultiPHP INI Editor is available only where the provider has enabled it. If the editor is missing, the values are controlled by the host, and you will need to ask for changes.

Step 3: Align the PHP values

Set the values in a sequence that keeps the request body and memory consistent. cPanel’s two documents differ slightly in wording, so the table shows both and the practical choice that satisfies each.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Pair cPanel support article (April 11, 2026) cPanel WHM MultiPHP INI Editor documentation Practical choice
post_max_size against upload_max_filesize At least as large Larger than upload_max_filesize Make post_max_size clearly larger, leaving room for form fields
memory_limit against post_max_size At least as large post_max_size smaller than memory_limit Set memory_limit above post_max_size, and confirm the host allows that amount

The WHM documentation puts it directly: “We strongly recommend that you set this value larger than the upload_max_filesize value and smaller than the memory_limit value.” That sentence describes post_max_size. cPanel’s support article also states a 2 GB ceiling for the PHP variables in its procedure. That ceiling is a documented limit, not proof that your plan permits uploads of that size.

Change only what you can see and what the evidence points to. Raise time limits when a long transfer fails and the host permits it, not as a general fix. Treat these relationships as configuration guidance, not as assurance that a large value is safe or allowed on your plan.

Step 4: Rule out upstream request-body limits

If the PHP values are high and the request still fails, the web server, reverse proxy, security layer, or host policy is likely rejecting the body before PHP runs. A 413 response is the clearest sign. You cannot fix that from the PHP editor. Shared-hosting customers often cannot edit the global server configuration, so the next step is a support request, not a further PHP change.

Step 5: Check quota and temporary capacity

For uploads through cPanel File Manager, open File Manager’s settings and check whether Max HTTP submission size has a custom value. cPanel’s File Manager article, dated May 22, 2026, says the default requires 5 MB of quota space to remain after the upload. Account administrators can change that requirement, so the value on your account may differ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Website uploads may also need temporary disk space while PHP stages and processes the file. If the PHP values look correct and the failure suggests storage is full, check remaining quota and ask the host about upload_tmp_dir and free space.

Step 6: Escalate with specific evidence

When the account cannot change the layer that is failing, a support request with exact details will be answered faster. Include:

  • The exact file size, in bytes or megabytes.
  • The upload endpoint, such as the WordPress media page or the File Manager path.
  • The timestamp, with time zone, and the HTTP status or error text.
  • The PHP version that serves the site and the values you recorded in Step 2.
  • Your question: which layer rejects the request, and whether the plan allows the cap you need.

WordPress’s PHP optimization handbook, last updated July 7, 2025, is direct about this: “Bear in mind that on shared hosting accounts, those limits are usually set on a server level and you may not be able to modify them or increase them above a certain value.”

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When the limit cannot be changed on your plan

Use a host-approved transfer route

If the host offers FTP or SFTP, a large file can be moved to the server outside the browser upload path. This changes the transfer route. It does not change your storage quota or the host’s rules about what can be stored, so check the quota before transferring. Use only the transfer methods your host documents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Compare plans on checkable limits

For a one-off upload, compare the available paths by maximum transfer size, whether they support resuming an interrupted transfer, the permissions your account has, and whether the destination application can use the file once it arrives.

For recurring large uploads, compare hosting plans on published limits, on which settings you can change yourself, on support response, on storage and quota, and on the transfer methods offered. A more expensive plan does not automatically fix upload problems. Ask the provider for the specific limit that matters to your workflow, and confirm it in writing before you pay for it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.