Release notes
154 versions · 865 changes
What changed in each version. Grouped by major release — these entries carry no dates.
Loading the version 5 changelog…
- Fixed an SQL injection security issue reported through Patchstack, affecting an upload identifier that was not fully sanitized.
- Updated all bundled libraries of the plugin and of the cloud extensions to their current versions.
- Bundled libraries are now under a plugin-specific namespace, so they can no longer conflict with libraries bundled by other plugins.
- Extensions are now published in variants built for different PHP versions, and each site receives the variant matching its own PHP version. Pro
- Extensions are no longer loaded if the site's PHP version is lower than the one they require. Pro
- Removed the Facebook SDK, which was bundled but never used. Pro
- Messenger notifications now use the Facebook Graph API version defined in the plugin's settings, instead of a hardcoded 2018 version. Pro
- Fixed Dropbox authorization failing silently. Pro
- Corrected the error reported when Dropbox is not activated. Pro
- Google Drive activation now reports a clear error when its authorization configuration cannot be retrieved, instead of a blank page. Pro
- Fixed uploading files to a NextGEN Gallery, which stopped working with recent versions of NextGEN Gallery. Pro
- The upload details page linked from Messenger notifications now works when WordPress is installed in a subdirectory, and is displayed within the site's theme instead of as plain text. Pro
- Fixed a fatal error on PHP 8 and later caused by an unquoted internal directory reference in the Dropbox, Facebook, NextGEN Gallery and Elementor extensions. Pro
- Fixed two functions that would stop working in PHP 9. Pro
- Fixed a warning where, after the libraries were placed under their own namespace, the minifier still referred to one of its own classes by its former name. Pro
- The plugin now rechecks its license when the server's PHP version changes. Pro
- The upload path setting now notes that cloud storage destinations exist in the Professional version; the note can be dismissed and does not return.
- Corrected outdated links and information in the plugin's documentation.
- Fixed bug where emails could not be sent after the release of the previous version.
- Verified compatibility with latest 7.0 WordPress version.
- Added uploadid length check in wfu_ajax_action_send_email_notification().
- Added wfu_params_*, wfu_gst_* and wfu_userstate_* in periodical cleanup.
- Added Transient Options section in Maintenance Actions tab.
- Fixed SQL injection issue CVSS 9.3 from Patchstack.
- Fixed File Overwrite Race Condition when uploading files with the same filename concurrently.
- Verified compatibility with latest 6.9 WordPress version.
- Fixed bug where a file could not be downloaded from Uploaded Files Dashboard menu.
- Fixed double-escaped HTML code of text when Pro version is deactivated. Pro
- Added support for FTP over TLS (FTPS) uploads.
- Fixed bug where the visual editor of the file viewer could not be invoked when there was no upload form on the same page. Pro
- Fixed bug where alt text and description in NGG image was not stored because NGG modified its API. Pro
- Fixed bug where the visual editor threw warnings for not finding personaldata when Personal Data were deactivated from the plugin's Settings in Dashboard.
- Fixed bug where a fatal error was thrown when updating the Pro version of the plugin and the extensions had to be reloaded. Pro
- Fixed bug where Link and Remotelink columns showed HTML code instead of links, due to excessive escaping. Pro
- Modified Messenger activation workflow due to withdrawal of Send To Messenger plugin from Meta. Pro
- Corrected bug where the upload form visual editor was not opening when Material UI theme was active.
- Corrected bug where notification emails were not sent when Material UI theme was active.
- Updated vendor libraries.
- Removal of Post Method setting from free version.
- Removal of curl_exec, file_get_contents and sockets from wfu_get_request() and wfu_post_request() of free version.
- Improvements on how AJAX endpoint is provided.
- Corrections to "Requires at least" value.
- Replacement of eval() in minification function.
- Corrected warning where translatable constants where loaded before the plugin textdomain was loaded.
- Further security improvements for compliance with wordpress.org.
- Added translation for all backend of the plugin.
- Modified plugin code so that all echoed variables to HTML are escaped.
- Modified code so that all input is sanitized, including all $_SERVER, $_COOKIE and $_SESSION input.
- Plugin name changed to Iptanus File Upload.
Loading the version 4 changelog…
Loading the version 3 changelog…
Loading the version 2 changelog…
Every version on one page, without JavaScript: the full changelog.
