Iptanus File Upload

Front-end file uploads for WordPress

Let visitors upload files from any page, post or sidebar widget — into your Media library, or straight to Dropbox, Google Drive, OneDrive, Amazon S3 or an FTP server.

Iptanus File Upload

What it does

A form on any page

One shortcode, or a Gutenberg block. Add your own fields, filter by size, extension or user role, and run several forms in the same post.

Files go where you need

The Media library, a NextGEN gallery, an FTP server or a cloud account. Large files upload in chunks, past the server’s own limit.

You see what arrives

A file browser and activity log in the dashboard, email notifications on upload, and a viewer your logged-in users can see too.

What it looks like

The upload form, as a visitor sees it
The Iptanus File Upload form as a visitor sees it: a file field with Select Files and Upload Files buttons, a subfolder chooser, a consent question, and a progress bar
The default form. Fields, buttons, labels and colours are all configurable.

Set-up and reference

Install it
  1. Install the plugin with the WordPress auto-installer, or download the .zip file from wordpress.org and install it from the Plugins section of your Dashboard.Or copy the wordpress_file_upload directory into the wp-content/plugins directory of your site yourself.
  2. Activate the plugin from the Plugins section of your Dashboard.
Put it on a page
  1. For an upload form, go to Dashboard / Settings / Iptanus File Upload and follow the instructions in Uploader Instances.[wordpress_file_upload]Or put the shortcode straight into the contents of any page.
  2. For a list of uploaded files, follow the instructions in Uploaded File List Instances instead.[wordpress_file_upload_browser]Or put the shortcode straight into the contents of any page.
Once it is running
  1. Open the page in your browser and you will see the upload form, or the list of files.
  2. View what has arrived from the Uploaded Files item in the Dashboard menu.
  3. Change the upload directory, or any other setting, from the small edit button at the top-left corner of the upload form.It opens the plugin options in a new window. If nothing appears, allow pop-up windows for your site.
  4. Full documentation of the plugin options is in the Options section below.

A handy Getting Started guide can be found here.

You can download the free version of the plugin by pressing the FREE version button below, or you can go for the professional version that offers multiple file uploads, captcha and much more by pressing the PRO version button. Professional licences are one-off, and their updates never expire.

Free versionPro version

The plugin offers many options for the two shortcodes, so that they can be tailored to any requirements. These options are available in the following links:

From version 2.4.1 filters and actions are supported in order to allow programmers to integrate Iptanus File Upload plugin with other plugins, extend its capabilities or perform advanced operations.

A detailed list of the plugin’s filters and actions can be found in this article.

The plugin is translated in the following languages:

Portuguese
kindly provided by Rui Alao
German
French
kindly provided by Thomas Bastide of omicronn.fr
Serbian
kindly provided by Andrijana Nikolic of webhostinggeeks.com
Dutch
kindly provided by Ruben Heynderycx
Chinese
kindly provided by Yingjun Li
Spanish
kindly provided by Marton
Italian
kindly provided by Enrico Marcolini marcuz.it
Polish
Swedish
kindly provided by Leif Persson marcuz.it
Persian
kindly provided by Shahriyar Modami chabokgroup.com
Greek

Translations in other languages are more than welcome!.

The plugin requires to have Javascript enabled in your browser. For Internet Explorer you also need to have Active-X enabled.

Please note that old desktop browsers or mobile browsers may not support all of the above features. In order to get full functionality use the latest versions of browsers, supporting HTML5, AJAX and CSS3.

You can read the Privacy Policy and Terms of Service of the plugin in the following links:

You can also read the Google Drive Privacy Policy and Terms of Service of the plugin in the following links:

Release notes

153 versions · 847 changes

What changed in each version. Grouped by major release — these entries carry no dates.

12 releases · 5.0.0 – 5.1.10 5 carry a security fix
  • Fixed bug where emails could not be sent after the release of the previous version.
  • Verified compatibility with latest 7.0 WordPress version.
  • Added uploadid length check in wfu_ajax_action_send_email_notification().
  • Added wfu_params_*, wfu_gst_* and wfu_userstate_* in periodical cleanup.
  • Added Transient Options section in Maintenance Actions tab.
  • Fixed SQL injection issue CVSS 9.3 from Patchstack.
  • Fixed File Overwrite Race Condition when uploading files with the same filename concurrently.
  • Verified compatibility with latest 6.9 WordPress version.
  • Fixed bug where a file could not be downloaded from Uploaded Files Dashboard menu.
  • Fixed double-escaped HTML code of text when Pro version is deactivated. Pro
  • Added support for FTP over TLS (FTPS) uploads.
  • Fixed bug where the visual editor of the file viewer could not be invoked when there was no upload form on the same page. Pro
  • Fixed bug where alt text and description in NGG image was not stored because NGG modified its API. Pro
  • Fixed bug where the visual editor threw warnings for not finding personaldata when Personal Data were deactivated from the plugin's Settings in Dashboard.
  • Fixed bug where a fatal error was thrown when updating the Pro version of the plugin and the extensions had to be reloaded. Pro
  • Fixed bug where Link and Remotelink columns showed HTML code instead of links, due to excessive escaping. Pro
  • Modified Messenger activation workflow due to withdrawal of Send To Messenger plugin from Meta. Pro
  • Corrected bug where the upload form visual editor was not opening when Material UI theme was active.
  • Corrected bug where notification emails were not sent when Material UI theme was active.
  • Updated vendor libraries.
  • Removal of Post Method setting from free version.
  • Removal of curl_exec, file_get_contents and sockets from wfu_get_request() and wfu_post_request() of free version.
  • Improvements on how AJAX endpoint is provided.
  • Corrections to "Requires at least" value.
  • Replacement of eval() in minification function.
  • Corrected warning where translatable constants where loaded before the plugin textdomain was loaded.
  • Further security improvements for compliance with wordpress.org.
  • Added translation for all backend of the plugin.
  • Modified plugin code so that all echoed variables to HTML are escaped.
  • Modified code so that all input is sanitized, including all $_SERVER, $_COOKIE and $_SESSION input.
  • Plugin name changed to Iptanus File Upload.
80 releases · 4.0.0 – 4.25.3 21 carry a security fix
                                                                                                                                                                  32 releases · 3.0.0 – 3.11.0 4 carry a security fix
                                                                                                                                                                                                                                  29 releases · 2.0.1 – 2.7.6 5 carry a security fix

                                                                                                                                                                                                                                                                                            Every version on one page, without JavaScript: the full changelog.

                                                                                                                                                                                                                                                                                            Free and Pro

                                                                                                                                                                                                                                                                                            The free version does not expire and is not a trial. Pro adds nineteen features. The full comparison and the price are on one page.

                                                                                                                                                                                                                                                                                            See pricing

                                                                                                                                                                                                                                                                                            894 discussions

                                                                                                                                                                                                                                                                                            Most recent: October 2025

                                                                                                                                                                                                                                                                                            Questions answered by Iptanus and other users.

                                                                                                                                                                                                                                                                                            1. Hi! Would it be possible to redirect users to the media attachment page that’s created once an image is uploaded to the Media Library?

                                                                                                                                                                                                                                                                                              When the upload form is embedded into /demopage/, and you upload a file named !!!mary-had-a-little-lamb.jpg, a child attachment is created as a new post (type “attachment”) and the slug is created from the file name by WordPress: /mary-had-a-little-lamb/ (no extension, cleared up special characters, etc). I’d like to auto-redirect to that slug /demopage/mary-had-a-little-lamb/.

                                                                                                                                                                                                                                                                                              1. Solved via a hack.

                                                                                                                                                                                                                                                                                                For those who need the same functionality:

                                                                                                                                                                                                                                                                                                1. I created a redirect page as decribed here: http://stackoverflow.com/questions/1698797/create-wordpress-page-that-redirects-to-another-url

                                                                                                                                                                                                                                                                                                2. My redirect page code then finds the latest attachment ID and redirects to it like this:

                                                                                                                                                                                                                                                                                                $args = array( ‘post_type’ => ‘attachment’, ‘posts_per_page’ => 1, ‘post_status’ =>’any’, ‘post_parent’ => 17 );
                                                                                                                                                                                                                                                                                                $attachments = get_posts( $args );
                                                                                                                                                                                                                                                                                                $redirect_id = 0;
                                                                                                                                                                                                                                                                                                if ( $attachments ) {
                                                                                                                                                                                                                                                                                                foreach ( $attachments as $attachment ) {
                                                                                                                                                                                                                                                                                                $redirect_id = $attachment->ID;
                                                                                                                                                                                                                                                                                                }
                                                                                                                                                                                                                                                                                                }

                                                                                                                                                                                                                                                                                                $header = ‘Location: http://localhost:8888/?attachment_id=‘ . $redirect_id;
                                                                                                                                                                                                                                                                                                header($header);
                                                                                                                                                                                                                                                                                                exit();

                                                                                                                                                                                                                                                                                                1. Well, in my case it redirects to the last attachment of the page with ID=17, but you could put ‘post_parent’ => null to get the last attachment globally, or conduct your search with different options altogether. And of course, adjust the URL in the $header variable to your liking or get it programmatically too.

                                                                                                                                                                                                                                                                                            2. Hi,

                                                                                                                                                                                                                                                                                              I am working on a form and I have a couple user data fields present in my shortcode that are not present on the page or in the additional data fields UI. When I add them to the additional data fields section they are added to the shortcode but if I leave the page and come back they are gone. I have attempted to include my shortcode below. Not sure if it will work…

                                                                                                                                                                                                                                                                                              [wordpress_file_upload multiple=”false” uploadpath=”national-photo-contest/%pagetitle%” captcha=”true” createpath=”true” duplicatespolicy=”reject” adminmessages=”true” debugmode=”true” placements=”title/filename+selectbutton/userdata/filelist/message/captcha/uploadbutton” uploadtitle=”Upload image” selectbutton=”Select Image/Select Images” uploadbutton=”Upload Image/Upload Images” successmessage=”Image %filename% uploaded successfully” warningmessage=”Image %filename% uploaded successfully but with warnings” errormessage=”Image %filename% not uploaded” waitmessage=”Image %filename% is being uploaded” widths=”plugin:60%, userdata:100%, userdata_label:100%, userdata_value:100%” heights=”plugin:100%” userdata=”true” userdatalabel=”Full Name|t:text|s:top|r:1|a:0|p:right|d:/Email Address|t:email|s:top|r:1|a:0|v:1|p:right|d:|g:0/Location where image was taken|t:text|s:top|r:1|a:0|p:top|d:/Description|t:multitext|s:top|r:1|p:top|d:/Facebook Username (Optional)|t:text|s:top|r:0|a:0|p:top|d:/Twitter Username (Optional)|t:text|s:top|r:0|a:0|p:top|d:/Instagram Username (Optional)|t:text|s:top|r:0|a:0|p:top|d:/Usage Rights|t:checkbox|s:top|r:1|a:0|p:top|d:|l:By uploading your photo you are giving Signs of God the right to use your image in any way that they deem necessary. If you are not comfortable with uploading your image for us to use please contact us at info@signs-of-god.com.|f:right”]

                                                                                                                                                                                                                                                                                              Thanks!

                                                                                                                                                                                                                                                                                                  1. Hi Nickolas,

                                                                                                                                                                                                                                                                                                    The “(” and “)” in the “(Optional)” piece of the title were breaking the shortcode. I removed that part and it is working as expected. Do you think I could use an escape character (\) to force the shortcode to ignore the parentheses?

                                                                                                                                                                                                                                                                                                    Thanks,

                                                                                                                                                                                                                                                                                                    Sean

                                                                                                                                                                                                                                                                                                    1. Here is how you can put the (Optional) keywork next to the label: just put the following css code inside the Custom CSS tab of the visual editor of the plugin:


                                                                                                                                                                                                                                                                                                      label#userdata_1_label_4:after, label#userdata_1_label_5:after, label#userdata_1_label_6:after {
                                                                                                                                                                                                                                                                                                      content: ' (Optional)';
                                                                                                                                                                                                                                                                                                      }

                                                                                                                                                                                                                                                                                                      Nickolas

                                                                                                                                                                                                                                                                                            3. Upload failed!
                                                                                                                                                                                                                                                                                              File not allowed.

                                                                                                                                                                                                                                                                                              Failed upload path: //wp-content/uploads/wedding/test/Screen-Shot-2017-01-05-at-13.52.15.png

                                                                                                                                                                                                                                                                                              [wordpress_file_upload singlebutton=”true” uploadpath=”uploads/wedding/test/” fitmode=”responsive” maxsize=”20″ createpath=”true” showtargetfolder=”true” subfoldertree=”auto” adminmessages=”true” debugmode=”true”]

                                                                                                                                                                                                                                                                                              I have set the directory to 777.
                                                                                                                                                                                                                                                                                              Is this a permissions problem?

                                                                                                                                                                                                                                                                                              1. Hi, no it is not a permission error but a security error. The plugin by default will not allow files having more than one dots (.) in the filename (they may contain double extensions which are suspicious). You can disable this additional security feature by going to Dashboard / Settings / WordPress File Upload / Advanced, locate option “Wildcard Asterisk Mode” and set it to ‘loose’.

                                                                                                                                                                                                                                                                                                Regards

                                                                                                                                                                                                                                                                                                Nickolas

                                                                                                                                                                                                                                                                                                  1. Yes it is in Pro version. In Free version you have to put the following in your functions.php file:

                                                                                                                                                                                                                                                                                                    if ( isset($GLOBALS["WFU_GLOBALS"]["WFU_WILDCARD_ASTERISK_MODE"]) ) $GLOBALS["WFU_GLOBALS"]["WFU_WILDCARD_ASTERISK_MODE"][3] = "loose";

                                                                                                                                                                                                                                                                                                    Nickolas

                                                                                                                                                                                                                                                                                                    1. Thanks Nickolas. Great plugin BTW.
                                                                                                                                                                                                                                                                                                      Think I’m going to “go Pro” anyway, just trying a couple more things out to make sure it satisfies all my requirements.

                                                                                                                                                                                                                                                                                            Ask a question

                                                                                                                                                                                                                                                                                            Answered by Iptanus, usually within a working day.

                                                                                                                                                                                                                                                                                            Ask a question

                                                                                                                                                                                                                                                                                            This site uses Akismet to reduce spam. Learn how your comment data is processed.

                                                                                                                                                                                                                                                                                            Scroll to Top