Iptanus File Upload
by nickboss · Forms
THIS IS FORMER WORDPRESS FILE UPLOAD PLUGIN. Simple yet powerful plugin to allow users to upload files from any page, post or sidebar and manage them.
88 health vs 63 average across 1,679 Forms plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Well optimized
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
16.5K
now · peak 41.4K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
8
releases in the last 12 months
6mo ago
latest release · v5.1.8
148
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 60% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “10K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,469 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Moveksdizajn7mo ago
so simple and works good
Read on wp.org ↗ - ★★★★★ laurendev1.6y ago
I was looking for a simple plugin for users to upload a singular jpeg or PDF to my website. This plugin rejects every file that is uploaded. I tried uploading several different types (jpeg, PDF and .doc) and it rejected all of them, saying each one was suspicious. The way around this according to the plugin page is to set up the Quarantine feature. But of course the quarantine feature is only possible by upgrading to the Premium version, rendering this app completely useless unless you pay to upgrade.
Read on wp.org ↗ - ★★★★★ revayatejahad2.3y ago
Thank you very much for your great work! well done! I have some issue with the plugin and It would be great if you help me with them as soon as possible. first of all, I use the plugin inside Gravity form and I want the uploaded link could be saved with the form entry! I’ve tried different ways but didn’t come with the result! finally I just added the %pathfile% in the comment below when file successfully uploaded as a way to see the uploaded link but I want this path be saved some where with the form. but the link will disappears when we move to next page or next file upload! secondly, in wordpress dashboard > uploaded files, it doesn’t show the file path with the domain name of ftp server but it shows the direct ftp address to the file which is not wanted! thirdly, It would be great if the plugin asks the domain name and replace it with the ftp file address at the beginning of each file link. lastly, it would be fantastic if the (uploaded files)’s links and names could be exported in an xlsx or csv file from wordpress dashboard > uploaded files.
Read on wp.org ↗ - ★★★★★ humananimal2.6y ago
thank you for this!!
Read on wp.org ↗ - ★★★★★ Marcel2.8y ago
The plugin is well-written and has a clean, logical interface. I am using it primarily for its webcam support, and it is working very well indeed. There is a currently a problem with uploading the resulting video to Dropbox or Google Drive; however, that is caused by another plugin that has a dependency on an outdated version of Guzzle (an HTTP client). Not only does the plugin work well, but Nickolas, the developer, delivers outstanding support. Highly recommended!
Read on wp.org ↗ - ★★★★★ LaurentAnimage3.0y ago
Do exactly what it should ! Very useful with a lot of shortcodes.Support is fast and precise.Very good plug.
Read on wp.org ↗ - ★★★★★ kwekli3.0y ago
This plugin is absolutely perfect and has everything one might need, especially in the pro version (awesome features that aren’t in the free version are listed there). If I was making a more serious website than I am currently working on, I’d definitely buy the pro version.
Read on wp.org ↗ - ★★★★★ qrmiz3.8y ago
I’m impressed how great this plugin is… There might be some bits glitching, from design perspective, but the overall how it works is just amazing… Good job to the author!!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 5.1.7 fixed File Overwrite Race Condition when uploading files with the same filename concurrently 5.1.7
- — Version 5.1.6 verified compatibility with latest 6.9 WordPress version 5.1.6
- — Version 5.1.5 added support for FTP over TLS (FTPS) uploads 5.1.5
- — Version 5.1.4 fixed bug where the visual editor throwed warnings for not finding personaldata when Personal Data were deactivated from the plugin’s Settings in Dashboard corrected bug where the upload form visual editor was not openin 5.1.4
- — Version 5.1.3 removed Post Method setting all GET and POST requests are now executed using the default WordPress functions 5.1.3
- — Version 5.1.2 improvements on how AJAX endpoint is provided corrections to Requires at lease value replacement of eval() in minification function 5.1.2
Known vulnerabilities
via Wordfence Intelligence32 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-05 CVE-2026-66447 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.7 Patched in 5.1.8
- 2026-08-03 CVE-2026-17044 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.7 Patched in 5.1.8
- 2025-01-07 CVE-2024-11635 Improper Control of Generation of Code ('Code Injection') Affects <= 4.24.12 Patched in 4.24.14
- Critical · 9.8 WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion ↗2025-01-07 CVE-2024-11613 Improper Control of Generation of Code ('Code Injection') Affects <= 4.24.15 Patched in 4.25.0
- 2025-01-07 CVE-2024-9939 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.24.13 Patched in 4.24.14
- Critical · 9.8 WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php ↗2024-10-11 CVE-2024-9047 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.24.11 Patched in 4.24.12
- High · 7.2 WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload ↗2024-08-15 CVE-2024-7301 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.8 Patched in 4.24.9
- 2024-07-16 CVE-2024-6494 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.7 Patched in 4.24.8
- 2024-07-16 CVE-2024-6651 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.7 Patched in 4.24.8
- 2024-07-15 CVE-2024-5852 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.24.7 Patched in 4.24.8
- Medium · 6.4 WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2024-03-29 CVE-2024-2847 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.5 Patched in 4.24.6
- 2023-11-14 Cross-Site Request Forgery (CSRF) Affects <= 4.24.0 Patched in 4.24.1
- Medium · 4.4 Wordpress File Upload <= 4.23.2 - Authenticated(Administrator+) Stored Cross-Site Scripting ↗2023-09-12 CVE-2023-4811 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.23.3 Patched in 4.23.3
- 2023-05-23 CVE-2023-2767 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.19.1 Patched in 4.19.2
- Medium · 4.9 WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal ↗2023-05-23 CVE-2023-2688 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.19.1 Patched in 4.19.2
- 2022-05-15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.3 Patched in 4.16.4
- Medium · 6.5 WordPress File Upload / WordPress File Upload Pro <= 4.16.2 - Authenticated (Contributor+) Path Traversal ↗2022-03-01 CVE-2021-24962 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.16.2 Patched in 4.16.3
- Medium · 5.4 WordPress File Upload <= 4.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Malicious SVG ↗2022-02-14 CVE-2021-24960 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.3 Patched in 4.16.3
- Medium · 5.4 WordPress File Upload <= 4.16.2 - Authenticated Stored Cross-Site Scripting via Shortcode ↗2022-02-14 CVE-2021-24961 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.3 Patched in 4.16.3
- 2020-03-13 CVE-2020-10564 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.12.2 Patched in 4.13.0
- 2018-04-06 CVE-2018-9844 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.3.4 Patched in 4.3.4
- 2018-03-31 CVE-2018-9172 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.3.3 Patched in 4.3.3
- Critical · 9.8 WordPress File Upload < 3.9.0 - Arbitrary File Upload ↗2016-06-23 Unrestricted Upload of File with Dangerous Type Affects < 3.9.0 Patched in 3.9.0
- Critical · 9.8 WordPress File Upload <= 3.4.0 - Arbitrary File Upload ↗2015-10-29 CVE-2015-9341 Unrestricted Upload of File with Dangerous Type Affects < 3.4.1 Patched in 3.4.1
- Critical · 9.8 WordPress File Upload < 3.0.0 - Arbitrary File Upload ↗2015-07-02 CVE-2015-9340 Unrestricted Upload of File with Dangerous Type Affects < 3.0.0 Patched in 3.0.0
- 2015-05-09 CVE-2015-9339 Unrestricted Upload of File with Dangerous Type Affects < 2.7.1 Patched in 2.7.1
- Critical · 9.8 WordPress File Upload <= 2.4.6 - Arbitrary File Upload ↗2015-01-23 CVE-2015-9338 Unrestricted Upload of File with Dangerous Type Affects <= 2.4.6 Patched in 2.5.0
- 2014-08-20 CVE-2014-125110 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.4.3 Patched in 2.4.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 11 languages, 0 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-10-29 20K+ → 10K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Store file uploads for Contact Form 7 1K+ installs · 4.3★ · 3 shared tags A -
Post Lists View Custom 2K+ installs · 3.9★ · 2 shared tags D -
Custom Post Type Attachment 700+ installs · 4.1★ · 2 shared tags C -
MC4WP: Mailchimp for WordPress 1M+ installs · 4.8★ · 1 shared tag A -
Post Type Switcher 200K+ installs · 4.7★ · 1 shared tag A - M MW WP Form 200K+ installs · 4.1★ · 1 shared tag A
Embed this report card
Drop a live Pulse card for Iptanus File Upload into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wp-file-upload" width="480" height="300" style="border:0" loading="lazy" title="Iptanus File Upload — Plugin Pulse"></iframe> Iptanus File Upload: 10K+ active installs, 4.4★ (117 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/wp-file-upload