{"id":171096,"date":"2023-04-04T18:49:16","date_gmt":"2023-04-04T18:49:16","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/frontend-file-upload\/"},"modified":"2026-08-23T17:52:43","modified_gmt":"2026-08-23T17:52:43","slug":"frontend-file-upload","status":"publish","type":"plugin","link":"https:\/\/kaa.wordpress.org\/plugins\/frontend-file-upload\/","author":18450283,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.0","stable_tag":"1.4.0","tested":"7.1.1","requires":"5.0","requires_php":"7.0","requires_plugins":null,"header_name":"Frontend File Upload","header_author":"Muneeb Khan","header_description":"Allows users to upload files from frontend directly in WordPress storage","assets_banners_color":"85299b","last_updated":"2026-08-23 17:52:43","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.fiverr.com\/muneebk21","header_plugin_uri":"https:\/\/github.com\/MuneebKhan1996","header_author_uri":"https:\/\/www.fiverr.com\/muneebk21","rating":5,"author_block_rating":0,"active_installs":60,"downloads":3480,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"muneebkhan21","date":"2023-04-04 19:06:29"},"1.0.1":{"tag":"1.0.1","author":"muneebkhan21","date":"2023-07-24 17:06:05"},"1.4.0":{"tag":"1.4.0","author":"muneebkhan21","date":"2026-08-23 17:52:43"}},"upgrade_notice":{"1.1.0":"<p>Security release. Anonymous file upload and anonymous file deletion (both\nunintended) are removed; the upload form now requires visiting the page it&#039;s\non (for a valid nonce), and deleting files now requires an administrator\naccount. Update as soon as possible.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.jpg":{"filename":"icon-128x128.jpg","revision":2893844,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.jpg":{"filename":"icon-256x256.jpg","revision":2893844,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":2893844,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500-rtl.png":{"filename":"banner-1544x500-rtl.png","revision":2893844,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":2893844,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250-rtl.png":{"filename":"banner-772x250-rtl.png","revision":2893844,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner-772x250.png":{"filename":"banner-772x250.png","revision":2893844,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.4.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpeg":{"filename":"screenshot-1.jpeg","revision":2893844,"resolution":"1","location":"assets","locale":"","width":677,"height":430},"screenshot-2.jpeg":{"filename":"screenshot-2.jpeg","revision":2893844,"resolution":"2","location":"assets","locale":"","width":767,"height":652}},"screenshots":{"1":"<strong>Frontend Display<\/strong> - Frontend form to allow users to upload files. screenshot-1.jpg","2":"<strong>Backend Display<\/strong> - Lists files uploaded by users. screenshot-2.jpg"}},"plugin_section":[],"plugin_tags":[260,2250,1263],"plugin_category":[],"plugin_contributors":[219692],"plugin_business_model":[],"class_list":["post-171096","plugin","type-plugin","status-publish","hentry","plugin_tags-file","plugin_tags-frontend","plugin_tags-uploader","plugin_contributors-muneebkhan21","plugin_committers-muneebkhan21"],"banners":{"banner":"https:\/\/ps.w.org\/frontend-file-upload\/assets\/banner-772x250.png?rev=2893844","banner_2x":"https:\/\/ps.w.org\/frontend-file-upload\/assets\/banner-1544x500.png?rev=2893844","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/frontend-file-upload\/assets\/icon.svg?rev=2893844","icon":"https:\/\/ps.w.org\/frontend-file-upload\/assets\/icon.svg?rev=2893844","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/frontend-file-upload\/assets\/screenshot-1.jpeg?rev=2893844","caption":"<strong>Frontend Display<\/strong> - Frontend form to allow users to upload files. screenshot-1.jpg"},{"src":"https:\/\/ps.w.org\/frontend-file-upload\/assets\/screenshot-2.jpeg?rev=2893844","caption":"<strong>Backend Display<\/strong> - Lists files uploaded by users. screenshot-2.jpg"}],"raw_content":"<!--section=description-->\n<p>Frontend File Uploader allows admins to add a simple form on frontend of WordPress website to enable their users to upload files directly in WordPress database.<\/p>\n\n<p>Using this Shortcode: [ffu-shortcode]<\/p>\n\n<p>Below are some salient features:<\/p>\n\n<h3>Frontend File Uploader Features<\/h3>\n\n<ul>\n<li>Simple to use<\/li>\n<li>100% responsive<\/li>\n<li>No limitation on the number of files<\/li>\n<li>Easy to add anywhere using a shortcode.<\/li>\n<li>Drag-and-drop upload zone with a live progress bar.<\/li>\n<li>Multi-file preview grid (image thumbnails, icons for other file types) before submitting.<\/li>\n<li>Allowed file types and maximum file size are configurable from File Uploader &gt; Settings.<\/li>\n<li>You can manage the uploaded files in WordPress admin panel.<\/li>\n<\/ul>\n\n<h4>Do you want to contribute?<\/h4>\n\n<p>If you have ideas that can help us improve our plugin and user experience, please contact us at rmkhan1996@hotmail.com\nA few notes about the sections above:<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Download the plugin.<\/li>\n<li>Upload 'frontend-file-upload.zip' to the '\/wp-content\/plugins\/' directory to your web server.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>Visit the plugin page for settings.<\/li>\n<\/ol>\n\n<!--section=changelog-->\n<h4>1.4.0<\/h4>\n\n<p>UI polish, front-end and admin. No functional or breaking changes; markup\nclasses changed throughout, so any custom CSS overriding the plugin's old\nclass names will need to be updated.<\/p>\n\n<ul>\n<li>Improved: front-end upload form redesigned with a card layout, a\ndynamic \"Accepted: ... Max size: ...\" hint on the dropzone (reflects\ncurrent settings), and an upload progress percentage readout.<\/li>\n<li>Improved: File Uploader admin list now uses WordPress's native list-table\nstyling, adds an \"Uploaded\" date column, a select-all checkbox, a\nconfirmation prompt before deleting, and an empty state when nothing's\nbeen uploaded yet.<\/li>\n<li>Fixed: the admin file list previously used invalid HTML (\/\ninside a <\/li>\n<\/ul>\n\n<p>&lt;<\/p>\n\n<p>table&gt;) and a hardcoded MIME filter that predated the\n  Settings page, so it silently excluded image uploads. Both are fixed.\n* Fixed: the \"Delete Selected\" button used non-existent CSS classes and\n  had no styling at all; now uses standard WP admin button styles and\n  disables itself until a file is selected.\n* Accessibility: the username field's label is now properly associated\n  with its input, and the settings page's file-size field is now\n  labeled.<\/p>\n\n<h4>1.3.0<\/h4>\n\n<p>Performance release. No breaking changes.<\/p>\n\n<ul>\n<li>Perf: the plugin's front-end CSS\/JS no longer load on every page of the\nsite. They're now only enqueued on pages where [ffu-shortcode] is\nactually rendered.<\/li>\n<li>Perf: the plugin's admin CSS\/JS no longer load on every wp-admin screen.\nThey're now scoped to the plugin's own File Uploader and Settings pages.<\/li>\n<li>Note: the upload flow already moved to async\/AJAX with a progress bar in\n1.2.0, which covers the \"avoid full-page reload\" part of this release's\nperformance work.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<p>New functionality. No breaking changes for site visitors; if you customized\nthe plugin's markup, JS, or CSS in a child theme or override, note the\nmarkup and script changes described below.<\/p>\n\n<ul>\n<li>New: drag-and-drop upload zone, alongside the existing click-to-browse\nfile input.<\/li>\n<li>New: multi-file preview grid shown before submitting, with image\nthumbnails, a generic icon for other file types, and a per-file remove\nbutton.<\/li>\n<li>New: uploads now go over AJAX with a real progress bar, instead of a\nfull-page form submission. The original full-page POST handler is kept\nas an automatic fallback if JavaScript is unavailable, so the form keeps\nworking either way.<\/li>\n<li>New: File Uploader &gt; Settings admin page to configure which file types\nare accepted and the maximum file size, replacing the previous hardcoded\npdf\/doc\/docx and 5MB limit. Existing sites keep that same default\nbehavior until the settings are changed.<\/li>\n<li>Dev note: the public JS file, form markup, and admin-ajax action names\nchanged substantially in this release. If anything hooks into or\noverrides this plugin's front-end templates or scripts directly, it will\nneed to be re-checked against the new markup.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<p>Security hardening release. If you have anything scripted against the upload\nform or the admin delete action, read the \"Breaking changes\" note below.<\/p>\n\n<ul>\n<li>Security: the upload handler previously ran on every front-end page load\nand accepted files from anyone, with no login, capability, or CSRF check.\nIt now requires a valid nonce, so it only accepts submissions from the\nplugin's own form.<\/li>\n<li>Security: the \"delete uploaded file\" admin action was reachable by\nlogged-out visitors and could delete any post or page by slug (not just\nattachments), bypassing WordPress's normal post-deletion process. It now\nrequires a valid nonce, requires the <code>manage_options<\/code> capability, is no\nlonger reachable while logged out, and only deletes actual attachments\n(via <code>wp_delete_attachment()<\/code>, which also removes the file from disk).<\/li>\n<li>Security: uploaded files are now validated server-side against their real\ncontent (not just file extension), independent of the <code>accept<\/code> attribute\non the file input.<\/li>\n<li>Security: server-side maximum file size (5MB by default), enforced\nregardless of any client-side checks.<\/li>\n<li>Security: uploaded filenames are now randomized to prevent overwrite\ncollisions and to stop uploaded files from being predictable\/enumerable.<\/li>\n<li>Security: added a basic per-IP rate limit (10 uploads per 10 minutes) on\nthe upload endpoint.<\/li>\n<li>Fix: the uploaded-by name field is now sanitized before being stored;\npreviously it was written to the database unsanitized.<\/li>\n<li>Fix: corrected a truncated .docx MIME type (both in the form's <code>accept<\/code>\nattribute and in the admin file listing query) that meant .docx files\nwere never actually matched by name.<\/li>\n<li>Fix: corrected an operator-precedence bug in the admin file-listing query.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<p>Initial release.<\/p>","raw_excerpt":"Allows users to upload files directly in WordPress Database from frontend.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/171096","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=171096"}],"author":[{"embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/muneebkhan21"}],"wp:attachment":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=171096"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=171096"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=171096"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=171096"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=171096"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=171096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}