WordPress.org

Plugin Directory

WordPress File Upload

Simple yet very powerful plugin to allow users to upload files to your website from any page and manage the uploaded files

3.9.0

  • a big number of extensions have been blacklisted for preventing upload of potentially dangerous files
  • the plugin will not allow inclusion, renaming or downloading of files with blacklisted extensions based on the new list
  • if no upload extensions are defined or the uploadpattern is too generic, then the plugin will allow only specific extensions based on a white list of extensions; if the administrator wants to include more extensions he/she must declare them explicitely
  • the use of the wildcard asterisk symbol has become stricter, asterisk will match all characters except the dot (.), so the default . pattern will allow only one extension in the filename (and not more as happened so far).
  • added environment variable 'Wildcard Asterisk Mode' for defining the mode of the wildcard asterisk symbol. If it is 'strict' (default) then the asterisk will not match dot (.) symbol. If it is 'loose' then the asterisk will match any characters (including dot).
  • slight bug fixes so that wildcard syntax works correctly with square brackets
  • added maximum number of uploads per specific interval in order to avoid DDOS attacks
  • added environment variables related to Denial-Of-Service attacks in order to configure the behaviour of the DOS attack checker
  • bug fix of wfu_before_file_upload filter that was not working correctly with files larger than 1MB

3.8.5

  • added bulk actions feature in File Browser in Dashboard for admins
  • added delete and include bulk actions in File Browser
  • improvement of column sort functionality of File Browser
  • added environment variable 'Use Alternative Randomizer' in order to make string randomizer function work for fast browsers
  • uploadedbyuser and userid fields became int to cope with large user ID numbers on some WordPress environments

3.8.4

  • dublicatespolicy attribute replaced by grammaticaly correct duplicatespolicy, however backward compatibility with the old attribute is maintained

3.8.3

  • fixed bug of subdirectory selector that was not initializing correctly after upload
  • fixed slight widget incompatibility with customiser
  • fixed bug of drag-n-drop feature that was not working when singlebutton operation was activated

3.8.2

  • fixed bug in wfu_after_file_loaded filter that was not working and was overriden by obsolete wfu_after_file_completed filter
  • added option in plugin's Settings in Dashboard to include additional files in plugin's database
  • added feature in Dashboard File Browser for admins to include additional files in plugin's database

3.8.1

  • fixed bug with duplicate userdata IDs in HTML when using more than one userdata occurrences

3.8.0

  • added webcam option that enables webcam capture functionality
  • added webcammode atribute to define capture mode (screenshots, video or both)
  • added audiocapture attribute to define if audio will be captured together with video
  • added videowidth, videoheight, videoaspectratio and videoframerate attributes to constrain video dimensions and frame rate
  • added camerafacing attribute to define the camera source (front or back)
  • added maxrecordtime attribute to define the maximum record time of video
  • added uploadmediabutton, videoname and imagename attributes to define custom webcam-related labels
  • fixed bug that strips non-latin characters from filename when downloading files

3.7.3

  • improved filename sanitization function
  • added Chinese translation by Yingjun Li

3.7.2

  • added option to cancel upload
  • setting added so that upload does not fail when site_url and home_url are different
  • added attribute requiredlabel in uploader's shortcode that defines the required keyword
  • required keyword can now be styled separately from the user field label
  • add user fields in Media together with file
  • setting added so that userdata fields are shown in Media Library or not
  • added Dutch translation by Ruben Heynderycx

3.7.1

  • internal code modifications and slight bug corrections

3.7.0

  • significant code modifications to make the plugin pluggable, invisible to users
  • addition of before and after upload filters
  • correction of small bug in Shortcode Composer of File Viewer

3.6.1

  • Iptanus Services server for getting version info and other utilities is now secure (https)
  • fixed bug with wfu_path_abs2rel function when ABSPATH is just a slash
  • additional fixes and new features in Professional version

3.6.0

  • French translation improved
  • correction of minor bug at wfu_functions.php
  • code improvements in upload algorithm
  • wp_check_filetype_and_ext check moved after completion of file
  • added wfu_after_file_complete filter that runs right after is fully uploaded
  • improved appearance of plugin's area in Dashboard

3.5.0

  • textdomain changed to wp-file-upload to support the translation feature of wordpress.org
  • added option in Maintenance Actions of plugin's area in Dashboard to export uploaded file data
  • added pagination of non-admin logged user's Uploaded Files Browser
  • added pagination of front-end File List Viewer
  • added pagination of user permissions table in plugin's Settings
  • added pagination of Log Viewer
  • corrected bug in View Log that was not working when pressing on the link
  • improvements to View Log feature
  • improvements to file download function to avoid corruption of downloaded file due to set_time_limit function that may generate warnings
  • added wfu_before_frontpage_scripts filter that executes right before frontpage scripts and styles are loaded
  • added functionality to avoid incompatibilities with NextGen Gallery plugin

3.4.1

  • plugin's security improved to reject files that contain .php.js or similar extensions

3.4.0

  • added fitmode attribute to make the plugin responsive
  • added widget "WordPress File Upload Form", so that the uploader can be installed in a sidebar
  • changes to Shortcode Composer so that it can edit plugin instances existing in sidebars as widgets
  • changes to Uploader Instances in plugin's area in Dashboard to show also instances existing inside sidebars
  • added the ability to define dimensions (width and height) for the whole plugin
  • dimensioning of plugin's elements improved when fitmode is set to "responsive"
  • filter and non-object warnings of front-end file browser, appearing when DEBUG mode is ON, removed
  • bug fixed to front-end file browser to hide Shortcode Composer button for non-admin users
  • logic changed to front-end file browser to allow users to download files uploaded by other users
  • code changed to front-end file browser to show a message when a user attempts to delete a file that was not uploaded by him/her

3.3.1

  • bug corrected that was breaking plugin operation for php versions prior to 5.3
  • added a "Maintenance Actions" section in plugin's Dashboard page
  • added option in plugin's "Maintenance Actions" to completely clean the database log

3.3.0

  • userdatalabel attribute changed to allow many field types
  • added the following user data field types: simple text, multiline text, number, email, confirmation email, password, confirmation password, checkbox, radiobutton, date, time, datetime, listbox and dropdown list
  • added several options to configure the new user data fields: label text (to define the label of the field), label position (to define the position of the label in relation to the field), required option (to define if the field needs to be filled before file upload), do-not-autocomplete option (to prevent the browsers for completing the field automatically), validate option (to perform validity checks of the field before file upload depending on its type), default text (to define a default value), group id (to group fields together such as multiple radio buttons), format text (to define field formatting depending on the field type), typehook option (to enable field validation during typing inside the field), hint position (to define the position of the message that will be shown to prompt the user that a required field is empty or is not validated) as well as an option to define additional data depending on the field type (e.g. define list of items of a listbox or dropdown list)
  • Shortcode Composer changed to support the new user data fields and options
  • placement attribute can accept more than one instances of userdata
  • fixed bug not showing date selector of date fields in Shortcode Composer when working with Firefox or IE browsers
  • in some cases required userdata input field will turn red if not populated
  • shortcode_exists and wp_slash fixes for working before 3.6 WordPress version
  • minor bug fixes

3.2.1

  • removed 'form-field' class from admin table tr elements
  • corrected bug that was causing problems in uploadrole and uploaduser attributes when a username or role contained uppercase letters
  • uploadrole and uploaduser attributes logic modified; guests are allowed only if 'guests' word is included in the attribute
  • modifications to the download functionality script to be more robust
  • corrected bug that was not showing options below a line item of admin tables in Internet Explorer
  • several feature additions and bug fixes in Professional version

3.2.0

  • added option in plugin's settings to relax CSS rules so that plugin inherits theme styling
  • modifications in html and css of editable subfolders feature to look better
  • modifications in html and css of prompt message when a required userdata field is empty
  • PLUGINDIR was replaced by WP_PLUGIN_DIR so that the plugin can work for websites where the contents dir is other than wp-content
  • fixed bug that was not allowing Shortcode Composer to launch when the shortcode was too big
  • fixed bug that was causing front-end file list not to work properly when no instance of the plugin existed in the same page / post

3.1.2

  • important bug detected and fixed that was stripping slashes from post or page content when updating the shortcode using the shortcode composer

3.1.1

  • the previous version broke the easy creation of shortcodes through the plugin's settings in Dashboard and it has been corrected, together with some improvements

3.1.0

  • an important feature (front-end file browser) has been added in professional version 3.1.0
  • added port number support for uploads using ftp mode
  • corrected bug that was not showing correctly in file browser files that were uploaded using ftp mode
  • eliminated confirmbox warning showing in page when website's DEBUG mode is ON
  • eliminated warning: "Invalid argument supplied for foreach() in ...plugins/wordpress-file-upload-pro/lib/wfu_admin.php on line 384"
  • eliminated warning: "Notice: Undefined index: postmethod in /var/www/wordpress/wp-content/plugins/wordpress-file-upload-pro/lib/wfu_functions.php on line 1348"
  • eliminated warnings in plugin's settings in Dashboard

3.0.0

  • major version number has advanced because an important feature has been added in Pro version (logged users can browse their uploaded files through their Dashboard)
  • several code modifications in file browser to make the plugin more secure against hacking, some functionalities in file browser have slightly changed
  • new file browser cannot edit files that were not uploaded with the plugin and it cannot edit or create folders
  • upload path cannot be outside the wordpress installation root
  • files with extension php, js, pht, php3, php4, php5, phtml, htm, html and htaccess are forbidden for security reasons

2.7.6

  • added functionality in Dashboard to add the plugin to a page automatically
  • fixed bug that was not showing the Shortcode Composer because the plugin could not find the plugin instance when the shortcode was nested in other shortcodes

2.7.5

  • added German and Greek translation

2.7.4

  • added Serbian translation thanks to Andrijana Nikolic from http://webhostinggeeks.com/
  • bug fix with %blogid%, %pageid% and %pagetitle% that where not implemented in notification emails
  • in single button operation selected files are removed in case that a subfolder has not been previously selected or a required user field has not been populated
  • bug fixed in single file operation that allowed selection of multiple files through drag-and-drop
  • bug fixed with files over 1MB that got corrupted when maintaining files with same filename
  • dummy (test) Shortcode Composer button removed from the plugin's Settings as it is no longer useful
  • added support for empty (zero size) files
  • many code optimizations and security enhancements
  • fixed javascript errors in IE8 that were breaking upload operation
  • code improvements to avoid display of session warnings
  • added %username% in redirect link
  • added option in plugin's Settings in Dashboard to select alternative POST Upload method, in order to resolve errors like "http:// wrapper is disabled in the server configuration by allow_url_fopen" or "Call to undefined function curl_init()"
  • added filter action wfu_after_upload, where the admin can define additional javascript code to be executed on user's browser after each file is finished

2.7.3

  • important bug fix in Pro version
  • added wfu_before_email_notification filter
  • corrected bug not showing correctly special characters (double quotes and braces) in email notifications

2.7.2

  • important bug fix in Pro version, very slight changes in free version

2.7.1

  • fixed bug with faulty plugin instances appearing when Woocommerce plugin is also installed
  • Upload of javascript (.js) files is not allowed for avoiding security issues
  • fixed bug with medialink and postlink attributes that were not working correctly
  • when medialink or postlink is activated, the files will be uploaded to the upload folder of WP website
  • when medialink or postlink is activated, subfolders will be deactivated
  • added option in subfolders to enable the list to populate automatically
  • added option in subfolders the user to be able to type the subfolder
  • wfu_before_file_check filter can modify the target path (not only the file name)

2.7.0

  • corrected bug when deleting plugin instance from the Dashboard
  • corrected bug not finding "loading_icon.gif"

2.6.0

  • full redesign of the upload algorithm to become more robust
  • added improved server-side handling of large files
  • plugin shortcodes can be edited using the Shortcode Composer
  • added visual editor button on the plugin to enable administrators to change the plugin settings easily
  • corrected bug causing sometimes database overloads
  • slight improvements of subfolder option
  • improvements to avoid code breaking in ajax calls when there are php warnings or echo from WordPress environment or other plugins
  • improvements and bug fixes in uploader when classic (no AJAX) upload is selected
  • eliminated php warnings in shortcode composer
  • corrected bug that was not correctly downloading files from the plugin's File Browser
  • added better security when downloading files from the plugin's File Browser
  • fixed bug not correctly showing the user that uploaded a file in the plugin's File Browser
  • use of curl to perform server http requests was replaced by native php because some web servers do not have CURL installed
  • corrected bug in shortcode composer where userdata fields were not shown in variables drop down
  • added feature that prevents page closing if an upload is on progress
  • added forcefilename attribute to avoid filename sanitization
  • added ftppassivemode attribute for enabling FTP passive mode when FTP method is used for uploading
  • added ftpfilepermissions attribute for defining the permissions of the uploaded file, when using FTP method
  • javascript and css files are minified for faster loading

2.5.5

  • fixed serious bug not uploading files when captcha is enabled
  • fixed bug not redirecting files when email notification is enabled

2.5.4

  • mitigated issue with "Session failed" errors appearing randomly in websites
  • fixed bug not applying %filename% variable inside redirect link
  • fixed bug not applying new filename, which has been modified with wfu_before_file_upload filter, in email notifications and redirects
  • fixed bug where when 2 big files were uploaded at the same time and one failed due to failed chunk, then the progress bar would not go to 100% and the file would not be shown as cancelled

2.5.3

  • fixed bug not allowing redirection to work
  • fixed bug that was including failed files in email notifications on certain occasions
  • default value for uploadrole changed to "all"

2.5.2

  • fixed important bug in free version not correctly showing message after failed upload

2.5.1

  • fixed important bug in free version giving the same name to all uploaded files
  • fixed bug in free version not clearing completely the plugin cache from previous file upload

2.5.0

  • major redesign of upload algorithm to address upload issues with Safari for Mac and Firefox
  • files are first checked by server before actually uploaded, in order to avoid uploading of large files that are invalid
  • modifications to progress bar code to make progress bar smoother
  • restrict upload of .php files for security reasons
  • fixed bug not showing correctly userdata fields inside email notifications when using ampersand or other special characters in userdata fields

2.4.6

  • variables %blogid%, %pageid% and %pagetitle% added in email notifications and subject and %dq% in subject
  • corrected bug that was breaking Shortcode Composer when using more than ten attributes
  • corrected bug that was rejecting file uploads when uploadpattern attribute contained blank spaces
  • several code corrections in order to eliminate PHP warning messages when DEBUG mode is on
  • several code corrections in order to eliminate warning messages in Javascript

2.4.5

  • correction of bug when using userfields inside notifyrecipients

2.4.4

  • intermediate update to make the plugin more immune to hackers

2.4.3

  • correction of bug to allow uploadpath to receive userdata as parameter

2.4.2

  • intermediate update to address some vulnerability issues

2.4.1

  • added filters and actions before and after each file upload - check below Filters/Actions section for instructions how to use them
  • added storage of file info, including user data, in database
  • added logging of file actions in database - admins can view the log from the Dashboard
  • admins can automatically update the database to reflect the current status of files from the Dashboard
  • file browser improvements so that more information about each file (including any user data) are shown
  • file browser improvements so that files can be downloaded
  • filelist improvements to display correctly long filenames (Pro version)
  • filelist improvements to distinguish successful uploads from failed uploads (Pro version)
  • improvements of chunked uploads so that files that are not allowed to be uploaded are cancelled faster (Pro version)
  • corrected wrong check of file size limit for chunked files (Pro version)
  • added postlink attribute so that uploaded files are linked to the current page (or post) as attachments
  • added subfolderlabel attribute to define the label of the subfolder selection feature
  • several improvements to subfolder selection feature
  • default value added to subfolder selection feature
  • definition of the subfoldertree attribute in the Shortcode Composer is now done visually
  • %userid% variable added inside uploadpath attribute
  • userdata variables added inside uploadpath and notifyrecipients attributes
  • uploadfolder_label added to dimension items
  • user fields feature improvements
  • user fields label and input box dimensions are customizable
  • captcha prompt label dimensions are customizable (Pro version)
  • added gallery attribute to allow the uploaded files to be shown as image gallery below the plugin (Pro version)
  • added galleryoptions attribute to define options of the image gallery (Pro version)
  • added css attribute and a delicate css editor inside Shortcode Composer to allow better styling of the plugin using custom css (Pro version)
  • email feature improved in conjunction with redirection
  • improved interoperability with WP-Filebase plugin
  • improved functionality of free text attributes (like notifymessage or css) by allowing double-quotes and brackets inside the text (using special variables), that were previously breaking the plugin

2.3.1

  • added option to restore default value for each attribute in Shortcode Composer
  • added support for multilingual characters
  • correction of bug in Shortcode Composer that was not allowing attributes with singular and plural form to be saved
  • correction of bug that was not changing errormessage attribute in some cases

2.2.3

  • correction of bug that was freezing the Shortcode Composer in some cases
  • correction of bug with successmessage attribute

2.2.2

  • serious bug fixed that was breaking operation of Shortcode Composer and File Browser when the WordPress website is in a subdirectory

2.2.1

  • added file browser in Dashboard for admins
  • added attribute medialink to allow uploaded files to be shown in Media
  • serious bug fixed that was breaking the plugin because of preg_replace_callback function
  • corrected error in first attempt to upload file when captcha is enabled

2.1.3

  • variables %pagetitle% and %pageid% added in uploadpath.
  • bug fixes when working with IE8.
  • Shortcode Composer saves selected options
  • Easier handling of userdata variables in Shortcode Composer
  • correction of bug that allowed debugdata to be shown in non-admin users
  • reset.css removed from plugin as it was causing breaks in theme's css
  • correction of bug with WPFilebase Manager plugin

2.1.2

  • Several bug fixes and code reconstruction.
  • Code modifications so that the plugin can operate even when DEBUG mode is ON.
  • New attribute debugmode added to allow better debugging of the plugin when there are errors.

2.1.1

  • Bug fixes with broken images when WordPress website is in a subdirectory.
  • Replacement of glob function because is not allowed by some servers.

2.0.2

  • Bug fixes in Dashboard Settings Shortcode Composer.
  • Correction of important bug that was breaking page in some cases.
  • Minor improvements of user data fields and notification email attributes.

2.0.1

This is the initial release of WordPress File Upload. Since this plugin is the successor of Inline Upload, the whole changelog since the creation of the later is included.

  • Name of the plugin changed to WordPress File Upload.
  • Plugin has been completely restructured to allow additional features.
  • A new more advanced message box has been included showing information in a more structured way.
  • Error detection and reporting has been improved.
  • An administration page has been created in the Dashboard Settings, containing a Shortcode Composer.
  • Some more options related to configuration of message showing upload results have been added.
  • Several bug fixes.

1.7.14

  • Userdata attribute changed to allow the creation of more fields and required ones.
  • Spanish translation added thanks to Maria Ramos of WebHostingHub.

1.7.13

  • Added notifyheaders attribute, in order to allow better control of notification email sent (e.g. allow to send HTML email).

1.7.12

  • Added userdata attribute, in order to allow users to send additional text data along with the uploaded file.

1.7.11

  • Added single button operation (file will be automatically uploaded when selected without pressing Upload Button).

1.7.10

  • Fixed bug with functionality of attribute filebaselink for new versions of WP-Filebase plugin.

1.7.9

  • Fixed problem with functionality of attribute filebaselink for new versions of WP-Filebase plugin.

1.7.8

  • More than one roles can now be defined in attribute uploadrole, separated by comma (,).

1.7.7

  • Variable %filename% now works also in redirectlink.

1.7.6

  • Changes in ftp functionality, added useftpdomain attribute so that it can work with external ftp domains as well.
  • Improvement of classic upload (used in IE or when setting forceclassic to true) messaging functionality.
  • Minor bug fixes.

1.7.5

  • Source modified so that it can work with WordPress sites that are not installed in root.
  • Added variable %blogid% for use with multi-site installations.
  • Bug fixes related to showing of messages.

1.7.4

  • Replacement of json2.js with another version.

1.7.3

  • CSS style changes to resolve conflicts with various theme CSS styles.

1.7.2

  • Added variable %useremail% used in notifyrecipients, notifysubject and notifymessage attributes.

1.7.1

  • Added capability to upload files outside wp-content folder.
  • Improved error reporting.

1.7

  • Complete restructuring of plugin HTML code, in order to make it more configurable and customizable.
  • Appearance of messages has been improved.
  • Added option to put the plugin in testmode.
  • Added option to configure the colors of success and fail messages.
  • Added option to modify the dimensions of the individual objects of the plugin.
  • Added option to change the placement of the individual objects of the plugin.
  • Improved error reporting.
  • Added localization for error messages.
  • Minor bug fixes.

1.6.3

  • Bug fixes to correct incompatibilities of the new ajax functionality when uploadrole is set to "all".

1.6.2

  • Bug fixes to correct incompatibilities of the new ajax functionality with redirectlink, filebaselink and adminmessages.

1.6.1

  • Correction of serious bug that prevented the normal operation of the plugin when the browser of the user supports HTML5 functionality.
  • Tags added to the plugin WordPress page.

1.6

  • Major lifting of the whole code.
  • Added ajax functionality so that file is uploaded without page reload (works in browsers supporting HTML5).
  • Added upload progress bar (works in browsers supporting HTML5).
  • Added option to allow user to select if wants to use the old form upload functionality.
  • File will not be saved again if user presses the Refresh button (or F5) of the page.
  • Translation strings updated.
  • Bug fixes for problems when there are more than one instances of the plugin in a single page.

1.5

  • Added option to notify user about upload directory.
  • Added option to allow user to select a subfolder to upload the file.

1.4.1

  • css corrections for bug fixes.

1.4

  • Added option to attach uploaded file to notification email.
  • Added option to customize message on successful upload (variables %filename% and %filepath% can be used).
  • Added option to customize color of message on successful upload.
  • "C:\fakepath\" problem resolved.
  • warning message about function create_directory() resolved.
  • css enhancements for compatibility with more themes.

1.3

  • Additional variables added (%filename% and %filepath%).
  • All variables can be used inside message subject and message text.
  • Added option to determine how to treat duplicates (overwrite existing file, leave existing file, leave both).
  • Added option to determine how to rename the uploaded file, when another file already exists in the target directory.
  • Added option to create directories and upload files using ftp access, in order to overcome file owner and SAFE MODE restrictions.
  • Added the capability to redirect to another web page when a file is uploaded successfully.
  • Added the option to show to administrators additional messages about upload errors.
  • Bug fixes related to interoperability with WP_Filebase

1.2

  • Added notification by email when a file is uploaded.
  • Added the ability to upload to a variable folder, based on the name of the user currently logged in.

1.1

Added the option to allow anyone to upload files, by setting the attribute uploadrole to "all".

1.0

Initial version.

Requires: 2.9.2 or higher
Compatible up to: 4.5.3
Last Updated: 1 month ago
Active Installs: 10,000+

Ratings

4.5 out of 5 stars

Support

9 of 24 support threads in the last two months have been marked resolved.

Got something to say? Need help?

Compatibility

+
=
Not enough data

1 person says it works.
0 people say it's broken.

100,1,1
0,1,0
50,2,1
50,2,1
100,1,1
100,1,1
50,2,1
100,1,1 100,1,1
100,1,1
100,1,1
100,1,1 50,2,1
0,1,0
100,1,1
100,1,1
100,1,1
100,1,1