Iptanus File Upload
Front-end file uploads for WordPress
Let visitors upload files from any page, post or sidebar widget — into your Media library, or straight to Dropbox, Google Drive, OneDrive, Amazon S3 or an FTP server.
What it does
A form on any page
One shortcode, or a Gutenberg block. Add your own fields, filter by size, extension or user role, and run several forms in the same post.
Files go where you need
The Media library, a NextGEN gallery, an FTP server or a cloud account. Large files upload in chunks, past the server’s own limit.
You see what arrives
A file browser and activity log in the dashboard, email notifications on upload, and a viewer your logged-in users can see too.
What it looks like
Set-up and reference
- Install the plugin with the WordPress auto-installer, or download the .zip file from wordpress.org and install it from the Plugins section of your Dashboard.Or copy the
wordpress_file_uploaddirectory into thewp-content/pluginsdirectory of your site yourself. - Activate the plugin from the Plugins section of your Dashboard.
- For an upload form, go to Dashboard / Settings / Iptanus File Upload and follow the instructions in Uploader Instances.
[wordpress_file_upload]Or put the shortcode straight into the contents of any page. - For a list of uploaded files, follow the instructions in Uploaded File List Instances instead.
[wordpress_file_upload_browser]Or put the shortcode straight into the contents of any page.
- Open the page in your browser and you will see the upload form, or the list of files.
- View what has arrived from the Uploaded Files item in the Dashboard menu.
- Change the upload directory, or any other setting, from the small edit button at the top-left corner of the upload form.It opens the plugin options in a new window. If nothing appears, allow pop-up windows for your site.
- Full documentation of the plugin options is in the Options section below.
A handy Getting Started guide can be found here.
You can download the free version of the plugin by pressing the FREE version button below, or you can go for the professional version that offers multiple file uploads, captcha and much more by pressing the PRO version button. Professional licences are one-off, and their updates never expire.
The plugin offers many options for the two shortcodes, so that they can be tailored to any requirements. These options are available in the following links:
From version 2.4.1 filters and actions are supported in order to allow programmers to integrate Iptanus File Upload plugin with other plugins, extend its capabilities or perform advanced operations.
A detailed list of the plugin’s filters and actions can be found in this article.
The plugin is translated in the following languages:
- Portuguese
- kindly provided by Rui Alao
- German
- French
- kindly provided by Thomas Bastide of omicronn.fr
- Serbian
- kindly provided by Andrijana Nikolic of webhostinggeeks.com
- Dutch
- kindly provided by Ruben Heynderycx
- Chinese
- kindly provided by Yingjun Li
- Spanish
- kindly provided by Marton
- Italian
- kindly provided by Enrico Marcolini marcuz.it
- Polish
- Swedish
- kindly provided by Leif Persson marcuz.it
- Persian
- kindly provided by Shahriyar Modami chabokgroup.com
- Greek
Translations in other languages are more than welcome!.
The plugin requires to have Javascript enabled in your browser. For Internet Explorer you also need to have Active-X enabled.
Please note that old desktop browsers or mobile browsers may not support all of the above features. In order to get full functionality use the latest versions of browsers, supporting HTML5, AJAX and CSS3.
You can read the Privacy Policy and Terms of Service of the plugin in the following links:
You can also read the Google Drive Privacy Policy and Terms of Service of the plugin in the following links:
Release notes
153 versions · 847 changes
What changed in each version. Grouped by major release — these entries carry no dates.
- Fixed bug where emails could not be sent after the release of the previous version.
- Verified compatibility with latest 7.0 WordPress version.
- Added uploadid length check in wfu_ajax_action_send_email_notification().
- Added wfu_params_*, wfu_gst_* and wfu_userstate_* in periodical cleanup.
- Added Transient Options section in Maintenance Actions tab.
- Fixed SQL injection issue CVSS 9.3 from Patchstack.
- Fixed File Overwrite Race Condition when uploading files with the same filename concurrently.
- Verified compatibility with latest 6.9 WordPress version.
- Fixed bug where a file could not be downloaded from Uploaded Files Dashboard menu.
- Fixed double-escaped HTML code of text when Pro version is deactivated. Pro
- Added support for FTP over TLS (FTPS) uploads.
- Fixed bug where the visual editor of the file viewer could not be invoked when there was no upload form on the same page. Pro
- Fixed bug where alt text and description in NGG image was not stored because NGG modified its API. Pro
- Fixed bug where the visual editor threw warnings for not finding personaldata when Personal Data were deactivated from the plugin's Settings in Dashboard.
- Fixed bug where a fatal error was thrown when updating the Pro version of the plugin and the extensions had to be reloaded. Pro
- Fixed bug where Link and Remotelink columns showed HTML code instead of links, due to excessive escaping. Pro
- Modified Messenger activation workflow due to withdrawal of Send To Messenger plugin from Meta. Pro
- Corrected bug where the upload form visual editor was not opening when Material UI theme was active.
- Corrected bug where notification emails were not sent when Material UI theme was active.
- Updated vendor libraries.
- Removal of Post Method setting from free version.
- Removal of curl_exec, file_get_contents and sockets from wfu_get_request() and wfu_post_request() of free version.
- Improvements on how AJAX endpoint is provided.
- Corrections to "Requires at least" value.
- Replacement of eval() in minification function.
- Corrected warning where translatable constants where loaded before the plugin textdomain was loaded.
- Further security improvements for compliance with wordpress.org.
- Added translation for all backend of the plugin.
- Modified plugin code so that all echoed variables to HTML are escaped.
- Modified code so that all input is sanitized, including all $_SERVER, $_COOKIE and $_SESSION input.
- Plugin name changed to Iptanus File Upload.
Every version on one page, without JavaScript: the full changelog.
Free and Pro
The free version does not expire and is not a trial. Pro adds nineteen features. The full comparison and the price are on one page.

Hi! Would it be possible to redirect users to the media attachment page that’s created once an image is uploaded to the Media Library?
When the upload form is embedded into /demopage/, and you upload a file named !!!mary-had-a-little-lamb.jpg, a child attachment is created as a new post (type “attachment”) and the slug is created from the file name by WordPress: /mary-had-a-little-lamb/ (no extension, cleared up special characters, etc). I’d like to auto-redirect to that slug /demopage/mary-had-a-little-lamb/.
Solved via a hack.
For those who need the same functionality:
1. I created a redirect page as decribed here: http://stackoverflow.com/questions/1698797/create-wordpress-page-that-redirects-to-another-url
2. My redirect page code then finds the latest attachment ID and redirects to it like this:
$args = array( ‘post_type’ => ‘attachment’, ‘posts_per_page’ => 1, ‘post_status’ =>’any’, ‘post_parent’ => 17 );
$attachments = get_posts( $args );
$redirect_id = 0;
if ( $attachments ) {
foreach ( $attachments as $attachment ) {
$redirect_id = $attachment->ID;
}
}
$header = ‘Location: http://localhost:8888/?attachment_id=‘ . $redirect_id;
header($header);
exit();
Well, in my case it redirects to the last attachment of the page with ID=17, but you could put ‘post_parent’ => null to get the last attachment globally, or conduct your search with different options altogether. And of course, adjust the URL in the $header variable to your liking or get it programmatically too.
Hi,
I am working on a form and I have a couple user data fields present in my shortcode that are not present on the page or in the additional data fields UI. When I add them to the additional data fields section they are added to the shortcode but if I leave the page and come back they are gone. I have attempted to include my shortcode below. Not sure if it will work…
[wordpress_file_upload multiple=”false” uploadpath=”national-photo-contest/%pagetitle%” captcha=”true” createpath=”true” duplicatespolicy=”reject” adminmessages=”true” debugmode=”true” placements=”title/filename+selectbutton/userdata/filelist/message/captcha/uploadbutton” uploadtitle=”Upload image” selectbutton=”Select Image/Select Images” uploadbutton=”Upload Image/Upload Images” successmessage=”Image %filename% uploaded successfully” warningmessage=”Image %filename% uploaded successfully but with warnings” errormessage=”Image %filename% not uploaded” waitmessage=”Image %filename% is being uploaded” widths=”plugin:60%, userdata:100%, userdata_label:100%, userdata_value:100%” heights=”plugin:100%” userdata=”true” userdatalabel=”Full Name|t:text|s:top|r:1|a:0|p:right|d:/Email Address|t:email|s:top|r:1|a:0|v:1|p:right|d:|g:0/Location where image was taken|t:text|s:top|r:1|a:0|p:top|d:/Description|t:multitext|s:top|r:1|p:top|d:/Facebook Username (Optional)|t:text|s:top|r:0|a:0|p:top|d:/Twitter Username (Optional)|t:text|s:top|r:0|a:0|p:top|d:/Instagram Username (Optional)|t:text|s:top|r:0|a:0|p:top|d:/Usage Rights|t:checkbox|s:top|r:1|a:0|p:top|d:|l:By uploading your photo you are giving Signs of God the right to use your image in any way that they deem necessary. If you are not comfortable with uploading your image for us to use please contact us at info@signs-of-god.com.|f:right”]
Thanks!
I should have added, here is the page where the form is rendered. http://www.signs-of-god.com/national-photo-contest/washington/
Thanks!
what if you remove the “(Optional)” word from Facebook, Twitter and Instagram?
Hi Nickolas,
The “(” and “)” in the “(Optional)” piece of the title were breaking the shortcode. I removed that part and it is working as expected. Do you think I could use an escape character (\) to force the shortcode to ignore the parentheses?
Thanks,
Sean
Here is how you can put the (Optional) keywork next to the label: just put the following css code inside the Custom CSS tab of the visual editor of the plugin:
label#userdata_1_label_4:after, label#userdata_1_label_5:after, label#userdata_1_label_6:after {
content: ' (Optional)';
}
Nickolas
Hi, can you please send me the URL of the page to check?
Regards
Nickolas
Hi Nickolas,
Here is the URL.
http://www.signs-of-god.com/national-photo-contest/washington/
Thanks,
Sean
so now all fields are shown, right?
Upload failed!
File not allowed.
Failed upload path: //wp-content/uploads/wedding/test/Screen-Shot-2017-01-05-at-13.52.15.png
[wordpress_file_upload singlebutton=”true” uploadpath=”uploads/wedding/test/” fitmode=”responsive” maxsize=”20″ createpath=”true” showtargetfolder=”true” subfoldertree=”auto” adminmessages=”true” debugmode=”true”]
I have set the directory to 777.
Is this a permissions problem?
Hi, no it is not a permission error but a security error. The plugin by default will not allow files having more than one dots (.) in the filename (they may contain double extensions which are suspicious). You can disable this additional security feature by going to Dashboard / Settings / WordPress File Upload / Advanced, locate option “Wildcard Asterisk Mode” and set it to ‘loose’.
Regards
Nickolas
I don’t have “Advanced” – is this only in the paid version?
Yes it is in Pro version. In Free version you have to put the following in your functions.php file:
if ( isset($GLOBALS["WFU_GLOBALS"]["WFU_WILDCARD_ASTERISK_MODE"]) ) $GLOBALS["WFU_GLOBALS"]["WFU_WILDCARD_ASTERISK_MODE"][3] = "loose";Nickolas
Thanks Nickolas. Great plugin BTW.
Think I’m going to “go Pro” anyway, just trying a couple more things out to make sure it satisfies all my requirements.