=== Iptanus File Upload === Contributors: nickboss Donate link: https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme Tags: file upload, upload form, front end upload, user uploads, webcam Requires at least: 3.0 Tested up to: 7.0 Stable tag: 5.2.0 License: GPLv3 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Front-end file upload forms for WordPress. Build them visually, add your own fields, and capture photos from a webcam. == Description == Let your visitors send you files — a job application, a photo for a contest, a signed PDF — straight from any page, post or sidebar of your WordPress site. Iptanus File Upload is a dedicated upload plugin, not a form builder with an upload field bolted on. Build the form by looking at it, with no shortcode syntax to learn. Add your own fields, so a file never arrives without you knowing who sent it or what it is for. Let people capture a photo straight from their camera instead of hunting for one on their phone. The free version is not a trial. No time limit, no artificial file size cap, no nag screens. It includes the Material UI theme, the visual editor, additional form fields and webcam capture. A Pro version adds cloud storage destinations, uploads of unlimited size, bulk and folder uploads, and file management from the dashboard. Most people run the free version for months before they need any of it. This plugin was formerly called WordPress File Upload. It has been developed continuously since 2013 and is currently at version 5.2.0. The characteristics of the plugin are: * It uses the latest HTML5 technology, however it will also work with old browsers and mobile phones. * It provides a nice upload form using Material UI React components. * It is compliant with the General Data Protection Regulation (GDPR) of the European Union. * It can be added in posts, pages or sidebars (as a widget). * It can capture and upload screenshots or video from the device's camera. * It supports additional form fields (like checkboxes, text fields, email fields, dropdown lists etc). * It can be used as a simple contact form to submit data (a selection of file can be optional). * It produces notification messages and e-mails. * It supports selection of destination folder from a list of subfolders. * Upload progress can be monitored with a progress bar. * Upload process can be cancelled at any time. * It supports redirection to another url after successful upload. * There can be more than one instances of the shortcode in the same page or post. * Uploaded files can be added to Media or be attached to the current page. * Uploaded files can be saved to an FTP location (ftp and sftp protocols supported). * It is highly customizable with many (more than 50) options. * It supports filters and actions before and after file upload. * It contains a visual editor for customizing the plugin easily without any knowledge of shortcodes or programming * It supports logging of upload events or management of files, which can be viewed by admins through the Dashboard. * It includes an Uploaded Files top-level menu item in the Dashboard, from where admins can view the uploaded files. * It includes a file browser in the Dashboard, from where admins can manage the files. * It supports multilingual characters and localization. The plugin is translated in the following languages: * Portuguese, kindly provided by Rui Alao * German * French, kindly provided by Thomas Bastide and improved by other contributors * Serbian, kindly provided by Andrijana Nikolic of http://webhostinggeeks.com/ * Dutch, kindly provided by Ruben Heynderycx * Chinese, kindly provided by Yingjun Li * Spanish, kindly provided by Marton * Italian, kindly provided by Enrico Marcolini https://www.marcuz.it/ * Polish * Swedish, kindly provided by Leif Persson * Persian, kindly provided by Shahriyar Modami http://chabokgroup.com * Greek Please note that the plugin contains minified CSS and Javascript files in order to reduce its size and speed-up performance. The unminified version of these files can be found [here](https://plugins.svn.wordpress.org/wp-file-upload/unminified/ "Unminified CSS and JS files of the plugin"). The source code of the compiled React files of the plugin can be found [here](https://sourceforge.net/p/wordpress-file-upload-react/code/ci/master/tree/ "React source code of the plugin"). Please also note that old desktop browsers or mobile browsers may not support all of the above functionalities. In order to get full functionality use the latest versions browsers, supporting HTML5, AJAX and CSS3. For more, consider [Iptanus File Upload Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing"): uploads straight to Google Drive, Dropbox, OneDrive or Amazon S3, files of unlimited size, many files or whole folders at once, drag and drop, per-file progress, captcha, an image gallery, custom CSS, and a file browser your users can reach from a page for everything that arrives. Please visit the **Other Notes** section for customization options of this plugin. == Installation == 1. First install the plugin using Wordpress auto-installer or download the .zip file from wordpress.org and install it from the Plugins section of your Dashboard or copy wordpress_file_upload directory inside wp-contents/plugins directory of your wordpress site. 1. Activate the plugin from Plugins section of your Dashboard. 1. In order to use the plugin simply go to the Dashboard / Settings / Iptanus File Upload and follow the instructions in Plugin Instances or alternatively put the shortcode [wordpress_file_upload] in the contents of any page. 1. Open the page on your browser and you will see the upload form. 1. You can change the upload directory or any other settings easily by pressing the small edit button found at the left-top corner of the upload form. A new window (or tab) with pop up with plugin options. If you do not see the new window, adjust your browser settings to allow pop-up windows. 1. Full documentation about the plugin options can be found at https://wordpress.org/plugins/wp-file-upload/other_notes/ or at https://www.iptanus.com/wordpress-plugins/iptanus-file-upload/ (including the Pro version) A getting started guide can be found at https://www.iptanus.com/getting-started-with-iptanus-file-upload-plugin/ == Frequently Asked Questions == = Will the plugin work in a mobile browser? = Yes, the plugin works on mobile browsers, including iOS and Android. = Can visitors upload without having an account? = Yes. By default every visitor can upload, including guests. You can also restrict uploading to particular user roles from the plugin's settings. = Does it work with Gutenberg, Elementor and other page builders? = Yes. The upload form is a shortcode, so it works anywhere a shortcode does — the block editor's Shortcode block, Elementor, and every other builder. Dedicated Gutenberg blocks and an Elementor widget, which let you place the form without touching a shortcode at all, are in the [Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing") version. = Can I send uploads straight to Google Drive, Dropbox or OneDrive? = Not in the free version — files are stored on your own site or sent to your own FTP server. Google Drive, Dropbox, Microsoft OneDrive and Amazon S3 destinations are in the [Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing") version. = How do you stop people uploading something malicious? = You can restrict uploads by file extension and by size. The plugin also sanitises and encodes everything passing between server and browser, so an uploaded file cannot turn into an attack on your dashboard. The Professional version adds a captcha before upload and a quarantine that holds a file for inspection when its extension and its actual content disagree. = What is the difference between the free and the Professional version? = The free version is a complete upload plugin — no time limit, no nag screens, and the plugin itself imposes no size cap. The Professional version adds uploads to Google Drive, Dropbox, OneDrive and Amazon S3, files of unlimited size that resume if the connection drops, selecting many files or whole folders at once, drag and drop, per-file progress, captcha, an image gallery, custom CSS, and a file browser your users can reach from a page. = Can I see the progress of the upload? = Yes. A progress bar appears while the file is being sent. The Professional version additionally shows details and a separate progress bar for each individual file. = Can I upload many files at the same time? = Yes, but not in the free version. If you want to allow multiple file uploads, please consider the [Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing") version. = Where do files go after upload? = Files by default are uploaded inside wp-content directory of your Wordpress website. To change it use attribute uploadpath. = Can I see and download the uploaded files? = Administrators can view all uploaded files together with associated field data from the plugin's Settings in Dashboard. The [Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing") version of the plugin allows users to view their uploaded files, either from the Dashboard, or from a page or post. = Are there filters to restrict uploaded content? = Yes, you can control allowed file size and file extensions by using the appropriate attribute (see Other Notes section). = Are there any upload file size limitations? = Yes, there are file size limitations imposed by the web server or the host. If you want to upload very large files, please consider the [Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing") version of the plugin, which surpasses size limitations. = Who can upload files? = By default all users can upload files. You can define which user roles are allowed to upload files. Even guests can be allowed to upload files. If you want to allow only specific users to upload files, then please consider the [Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing") version of the plugin. = What security is used for uploading files? = The plugin is designed not to expose website sensitive information. It has been tested by experts and verified that protects against CSRF and XSS attacks. All parameters passing from server to client side are encoded and sanitized. For higher protection, like use of captcha, please consider the [Professional](https://www.iptanus.com/pricing/?utm_source=wporg&utm_medium=readme "Iptanus File Upload pricing") version of the plugin. = What happens if connection is lost during a file upload? = In the free version the upload will fail. However in the Pro version the upload will resume and will continue until the file is fully uploaded. This is especially useful when uploading very large files. = The plugin does not look nice with my theme. What can I do? = There is an option in plugin's settings in Dashboard to relax the CSS rules, so that buttons and text boxes inherit the theme's styles. If additional styling is required, this can be done using CSS. The Professional version of the plugin allows CSS rules to be embed in the shortcode. == Screenshots == 1. One shortcode, and any page accepts files. 2. A progress bar, so nobody wonders whether it is working. 3. Clear confirmation — and an email to you, if you want one. 4. Collect a name, a reference, a category — alongside the file. 5. Let people choose where their file lands. 6. Works in a sidebar widget, not just a page. 7. Build the form visually. No code, no shortcode syntax. 8. Browse and search uploaded files from the WordPress dashboard. == Changelog == = 5.2.0 = * fixed an SQL injection security issue reported through Patchstack, affecting an upload identifier that was not fully sanitized * updated all bundled libraries to their current versions * bundled libraries are now under a plugin-specific namespace, so they can no longer conflict with libraries bundled by other plugins * the upload path setting now notes that cloud storage destinations exist in the Professional version; the note can be dismissed and does not return * corrected outdated links and information in the plugin's documentation = 5.1.10 = * fixed bug where emails could not be sent after the release of the previous version = 5.1.9 = * verified compatibility with latest 7.0 Wordpress version * added uploadid length check in wfu_ajax_action_send_email_notification() * added wfu_params_*, wfu_gst_* and wfu_userstate_* in periodical cleanup * added Transient Options section in Maintenance Actions tab = 5.1.8 = * fixed SQL injection issue CVSS 9.3 from Patchstack = 5.1.7 = * fixed File Overwrite Race Condition when uploading files with the same filename concurrently = 5.1.6 = * verified compatibility with latest 6.9 Wordpress version = 5.1.5 = * added support for FTP over TLS (FTPS) uploads = 5.1.4 = * fixed bug where the visual editor throwed warnings for not finding personaldata when Personal Data were deactivated from the plugin's Settings in Dashboard * corrected bug where the upload form visual editor was not opening when Material UI theme was active * corrected bug where notification emails were not sent when Material UI theme was active = 5.1.3 = * removed Post Method setting * all GET and POST requests are now executed using the default Wordpress functions = 5.1.2 = * improvements on how AJAX endpoint is provided * corrections to Requires at lease value * replacement of eval() in minification function = 5.1.1 = * further security improvements for compliance with wordpress.org = 5.1.0 = * added translation for all backend of the plugin * modified plugin code so that all echoed variables to HTML are escaped * modified code so that all input is sanitized, including all $_SERVER, $_COOKIE and $_SESSION input = 5.0.0 = * changed the name of the plugin to Iptanus File Upload. = 4.25.3 = * added nonce in wfu_edit_filedetails() function in order to avoid CSRF attacks. = 4.25.2 = * corrected bug in file downloader where files having spaces could not be downloaded = 4.25.1 = * slight changes in some notifications shown in Remarks column of View Log page = 4.25.0 = * modified View Log Remarks column to have a better look * fixed security issue that allowed directory traversals in wfu_downloader.php * fixed security issue that allowed unauthorized read of directory contents through wfu_ajax_action_read_subfolders() function = 4.24.15 = * loading of plugin text domain moved to init hook to avoid Wordpress warnings * added file_path in wfu_after_file_upload filter * corrected bug "Call to undefined function wfu_update_option()" in wfu_licensing_functions.php = 4.24.14 = * verified compatibility with Wordpress version 6.7 * modified wfu_downloader.php to read the necessary data from a temporary file in order to avoid XSS attacks and directory traversals * modified code so that the autoload value for all plugin options can be defined in wfu_get_all_plugin_options() function * set autoload value for most plugin options to false to improve page loading performance * added daily action to remove unnecessary wfu_queue_* options from the database * added alt tags for plugin images = 4.24.13 = * extended rar mime types = 4.24.12 = * verified compatibility with Wordpress version 6.6.2 * fixed directory traversal security issue in wfu_file_downloader.php file * extended csv, xml and m4a mime types = 4.24.11 = * corrected bug where files with extensions containing capital letters were rejected due to MIME check failure * corrected bug in Elementor extension that generated a warning when $post global variable is null = 4.24.10 = * corrected bug where FTP uploads where all rejected after release of version 4.24.9 due to fail of MIME type check = 4.24.9 = * verified compatibility with Wordpress version 6.6.1 * limited the number of whitelisted extensions to those having an associated MIME type, in order to avoid XSS attacks * added MIME type validation of uploaded files * added advanced variable WFU_MIMETYPE_VAL_EXCEPTIONS that enables exceptions when validating the MIME type of uploaded files * added scanning of textual uploaded file contents for detecting PHP and Javascript tags * added scanning of textual uploaded file contents for heuristic analysis and detection of suspicious content * added advanced variable WFU_FILESCAN_BUFFERSIZE that defines the size of the chunk when reading file contents sequencially * added advanced variable WFU_FILESCAN_OVERLAPSIZE that defines the size of the overlapping of the chunks when reading file contents sequencially * added advanced variable WFU_FILESCAN_SECURITY_LEVEL that defines the security level when scanning uploaded files = 4.24.8 = * verified compatibility with Wordpress version 6.5.5 * escaped userdata values in File Browser, File Details page and View Log, in order to avoid XSS attacks * removed the ability to upload files outside /wp-content folder, in order to avoid directory traversal attacks * removed the ability to edit the shortcode for authors and contributors, in order to avoid CSRF attacks * stripped tags and escaped dir query param in File Browser in order to avoid reflected XSS attacks = 4.24.7 = * verified compatibility with Wordpress version 6.5.2 * fixed bug in Date, Time and DateTime user fields that were not working when Material UI theme was active * added Country List user field that prompts the user to make a selection from a list of countries = 4.24.6 = * sanitized uploadbutton attribute input in order to protect against Stored XSS attacks * fixed bug not showing RecaptchaV2 captcha in the upload form when MaterialUI theme was active = 4.24.5 = * added external customizable templates folder /uploads/wfu_templates = 4.24.4 = * verified compatibility with Wordpress version 6.4.3 * added upload form option webcamstartoff to start webcam deactivated = 4.24.3 = * verified compatibility with Wordpress version 6.4.2 = 4.24.2 = * corrected bug where the plugin was generating a fatal PHP error during activation if allow_url_fopen was 0 * added debug log options in Maintenance Actions: activate/deactivate debug logging, download and reset debug log data = 4.24.1 = * verified compatibility with Wordpress version 6.4.1 * added nonce to visual editor and switched WFU_SHORTCODECOMPOSER_NOADMIN to false to avoid CSRF attacks through save_shortcode AJAX action = 4.24.0 = * verified compatibility with Wordpress version 6.3.2 = 4.23.3 = * added response header information in wfu_get_request() and wfu_post_request() functions * fixed security issue that could allow users with admin access to perform XSS attacks through the redirect link attribute = 4.23.2 = * verified compatibility with Wordpress version 6.3.1 = 4.23.1 = * corrected compatibility issue with Divi Theme Builder = 4.23.0 = * added Home Domain information in Main tab of Dashboard area of the plugin * corrected bug where and templates were not placed correctly inside the shadow DOM * added _wfu_file_upload_output_inner filter for customizing inner upload form HTML before it is processed by the templating system = 4.22.2 = * updated vendor libraries = 4.22.1 = * fixed bug in wfu_webcam_update_preview() function that was breaking upload form when uploadid was greater than 1 = 4.22.0 = * added webcamselfile attribute in upload form shortcode so that webcam can work in parallel with file selection * added webcamswitch attribute in upload form shortcode to enable/disable camera switch button in webcam * added WFU_WEBCAMSWITCHMODE advanced variable attribute that defines the camera switch mode, 'side' for switching between front and rear cameras, 'device' for switching between available video devices * added WFU_MEDIARECORDER_MIMETYPE advanced variable attribute that defines a specific MIME type for webcam MediaRecorder * added webcambg attribute that defines the background color of the webcam capture box * webcam video width and height changed so that they correspond to ideal resolution of the camera * webcam capture feature improved so that screenshots have the camera's resolution * webcam playback of recorded video is now working on iOS devices * added extended support of webcam feature for mobile devices * several other code improvements in webcam feature * correction of bugs related to wfuca_update_option() function in alternative Iptanus server = 4.21.7 = * fixed bug in wfu_exclude_notifications_from_comments() which crashes the website when Woocommerce is present = 4.21.6 = * improved webcam operation on iOS devices * code modifications to hide WFU admin notifications from Comments Dashboard menu page = 4.21.5 = * added Themes tab in upload form visual editor to select a theme * added MaterialUI theme in upload form * added upload form attributes to define basic colors and dark mode in Material UI theme * added color picker with transparency in plugin's visual editor * fixed small bug with time indication in webcam feature of the upload form = 4.20.0 = * added Notifications tab in Dashboard area of the plugin = 4.19.2 = * codes improvements in plugin settings to protect against XSS attacks * code improvements in backend file browser to avoid directory traversal attacks * permanent fix for compatibility with block themes = 4.19.1 = * updated vendor libraries to their latest version * added logging of start and end time in uploader metrics * added userdata in wfu_before_upload filter * fixed bugs when uploading in classic HTML forms mode = 4.19.0 = * added compatibility with block themes * added shortcode attribute blockcompatibility for controlling block theme compatibility = 4.18.1 = * fixed compatibility issues with PHP 8.1 or higher * changed uploadform logic so that CSS pseudoselectors for Select File button work = 4.18.0 = * minor bug fixes = 4.17.0 = * minor bug fixes = 4.16.4 = * sanitized page title in all places where it is retrieved to avoid XSS attacks = 4.16.3 = * improved sanitization and escaping of shortcode attributes to avoid XSS attacks * file type .svg moved to blacklist to avoid XSS attacks coming from scripts inside SVG files * added security check to forbid uploads inside wp-content/plugin directory * improved handling of videoname and imagename file uploader shortcode attributes to avoid directory traversal attacks * improved /lib and /extensions loader to avoid arbitrary code execution through injected image files * all wfu_blocks.php functions became redeclareable = 4.16.2 = * minor bug fixes in Pro version = 4.16.1 = * corrected $_SESSION variable problem in maintenance purge function = 4.16.0 = * visual editor edit button misalignment fixed * corrected echo problem when recording from webcam with sound = 4.15.0 = * COOKIEHASH bug corrected * credentials in FTP paths are stripped from the paths * corrected File Detais to File Details * regex "/