Release notes of Iptanus File Upload

Release notes

154 versions · 865 changes

What changed in each version. Grouped by major release — these entries carry no dates.

13 releases · 5.0.0 – 5.2.0 6 carry a security fix
  • Fixed an SQL injection security issue reported through Patchstack, affecting an upload identifier that was not fully sanitized.
  • Updated all bundled libraries of the plugin and of the cloud extensions to their current versions.
  • Bundled libraries are now under a plugin-specific namespace, so they can no longer conflict with libraries bundled by other plugins.
  • Extensions are now published in variants built for different PHP versions, and each site receives the variant matching its own PHP version. Pro
  • Extensions are no longer loaded if the site's PHP version is lower than the one they require. Pro
  • Removed the Facebook SDK, which was bundled but never used. Pro
  • Messenger notifications now use the Facebook Graph API version defined in the plugin's settings, instead of a hardcoded 2018 version. Pro
  • Fixed Dropbox authorization failing silently. Pro
  • Corrected the error reported when Dropbox is not activated. Pro
  • Google Drive activation now reports a clear error when its authorization configuration cannot be retrieved, instead of a blank page. Pro
  • Fixed uploading files to a NextGEN Gallery, which stopped working with recent versions of NextGEN Gallery. Pro
  • The upload details page linked from Messenger notifications now works when WordPress is installed in a subdirectory, and is displayed within the site's theme instead of as plain text. Pro
  • Fixed a fatal error on PHP 8 and later caused by an unquoted internal directory reference in the Dropbox, Facebook, NextGEN Gallery and Elementor extensions. Pro
  • Fixed two functions that would stop working in PHP 9. Pro
  • Fixed a warning where, after the libraries were placed under their own namespace, the minifier still referred to one of its own classes by its former name. Pro
  • The plugin now rechecks its license when the server's PHP version changes. Pro
  • The upload path setting now notes that cloud storage destinations exist in the Professional version; the note can be dismissed and does not return.
  • Corrected outdated links and information in the plugin's documentation.
  • Fixed bug where emails could not be sent after the release of the previous version.
  • Verified compatibility with latest 7.0 WordPress version.
  • Added uploadid length check in wfu_ajax_action_send_email_notification().
  • Added wfu_params_*, wfu_gst_* and wfu_userstate_* in periodical cleanup.
  • Added Transient Options section in Maintenance Actions tab.
  • Fixed SQL injection issue CVSS 9.3 from Patchstack.
  • Fixed File Overwrite Race Condition when uploading files with the same filename concurrently.
  • Verified compatibility with latest 6.9 WordPress version.
  • Fixed bug where a file could not be downloaded from Uploaded Files Dashboard menu.
  • Fixed double-escaped HTML code of text when Pro version is deactivated. Pro
  • Added support for FTP over TLS (FTPS) uploads.
  • Fixed bug where the visual editor of the file viewer could not be invoked when there was no upload form on the same page. Pro
  • Fixed bug where alt text and description in NGG image was not stored because NGG modified its API. Pro
  • Fixed bug where the visual editor threw warnings for not finding personaldata when Personal Data were deactivated from the plugin's Settings in Dashboard.
  • Fixed bug where a fatal error was thrown when updating the Pro version of the plugin and the extensions had to be reloaded. Pro
  • Fixed bug where Link and Remotelink columns showed HTML code instead of links, due to excessive escaping. Pro
  • Modified Messenger activation workflow due to withdrawal of Send To Messenger plugin from Meta. Pro
  • Corrected bug where the upload form visual editor was not opening when Material UI theme was active.
  • Corrected bug where notification emails were not sent when Material UI theme was active.
  • Updated vendor libraries.
  • Removal of Post Method setting from free version.
  • Removal of curl_exec, file_get_contents and sockets from wfu_get_request() and wfu_post_request() of free version.
  • Improvements on how AJAX endpoint is provided.
  • Corrections to "Requires at least" value.
  • Replacement of eval() in minification function.
  • Corrected warning where translatable constants where loaded before the plugin textdomain was loaded.
  • Further security improvements for compliance with wordpress.org.
  • Added translation for all backend of the plugin.
  • Modified plugin code so that all echoed variables to HTML are escaped.
  • Modified code so that all input is sanitized, including all $_SERVER, $_COOKIE and $_SESSION input.
  • Plugin name changed to Iptanus File Upload.
80 releases · 4.0.0 – 4.25.3 21 carry a security fix
                                                                                                                                                                  32 releases · 3.0.0 – 3.11.0 4 carry a security fix
                                                                                                                                                                                                                                  29 releases · 2.0.1 – 2.7.6 5 carry a security fix

                                                                                                                                                                                                                                                                                            Every version on one page, without JavaScript: the full changelog.

                                                                                                                                                                                                                                                                                            Scroll to Top