Out-of-the-Box | Best Dropbox Plugin for WP v3.9.10 Nulled
= 10 September 2026 = Security Fixes
Fixed cross-site scripting issues in the File Browser, Gallery, Embed and media player modules, and in the administration screens, where file and folder names, file descriptions and cloud account names were not escaped when displayed.
Fixed a cross-site scripting issue in the Proofing collection overview, where the file selection submitted by a visitor was shown to administrators without escaping.
Fixed a cross-site scripting issue in the WooCommerce upload box settings: the description and shortcode fields are now sanitized when saved and escaped when displayed, including values that were stored before this update.
Fixed cross-site scripting issues in the event log Dashboard: file and folder names, user names, module names and the additional data stored with an event were not escaped when the log table was rendered. An unauthenticated visitor could store script in the log that ran when an administrator opened the Dashboard.
Fixed an issue where a form field could reflect unvalidated input back into the page.
Improved protection against unauthorized cloud account connection requests.
Improved protection against unauthorized changes to the plugin settings.
WooCommerce upload requests now verify that the requested order item matches the module the request was made from.
Allowed file extensions are now enforced on the server for all uploads, including uploads that are sent directly to the cloud.
Maximum file size is now also checked on the server for direct uploads.
Proofing selections can no longer be created without limit by visitors, and the number of items per selection is now capped.
Added strict validation of the account, entry, folder, user, sorting and search parameters accepted by the file browser, upload, ZIP, download, thumbnail, search and dashboard requests, preventing PHP errors from malformed or manipulated requests.
Added type validation for cookie values, preventing a fatal PHP error on password-protected and dynamic-folder modules.
Cache keys, an outbound request header and an API request no longer contain unvalidated client input.
Sensitive authorization details are no longer written to debug logs.
New Features, Settings and Integrations
New Advanced > Block executable file uploads setting which will by default refuse cloud uploads of file types that can run as a program, like .exe, .bat, .lnk and .js.
Bug fixes
The media player skin name is now validated before it is used to load a skin, so that only a plain skin folder can be selected. Selecting a missing or invalid skin now falls back to the configured skin and then to the default skin, instead of failing.
Fixed the check on allowed file extensions so that a file name has to end with a real extension, and so that an invalid configuration no longer allows every file type.
Gravity Forms
The 'next' button on multi-page form configurations was not triggering the Upload action in Gravity Forms 3.x+.
Improvements
Health tests have been improved to check communication with cloud providers.
Cached file listings are cleared when users log in or log out.
The local thumbnail cache is now cleaned automatically and kept within a configurable size limit.
Visitor IP addresses are now determined from the web server instead of from headers that can be set by the visitor. Sites behind a reverse proxy or CDN can restore the previous behaviour with a filter.
Out-of-the-Box | Best Dropbox Plugin for WP v3.9.2 Nulled
= 26 August 2026 Bug fixes
The button to manually link personal folders was not opening the folder selection modal.
Divi Page Builder
Divi 5 modules could not always be rendered on the frontend due to missing block information.
Gravity Forms
The integration has been updated to remove the warning notices regarding scripts and styles that have not yet been loaded.
Improvements
Placeholder support has been added for form fields with multiple input fields, such as a first and last name input for a single name form field in Fluent Forms, for example.
Loading a module configuration via the Module Manager now provides visual feedback.
Out-of-the-Box | Best Dropbox Plugin for WP v3.9.0 Nulled Vulnerabilities Patched
An Arbitrary File Upload vulnerability in the media import function has been fixed. Previously, file types were not validated against the allowed MIME list in WordPress before being written to the uploads directory. This could allow a user with access to the Admin File Browser, or an unauthenticated visitor on sites using the specific shortcode parameters on a public module, to write an executable file to the server.
Improvements
The communication between the plugin and integrations has been completely reworked to provide full support for Document Isolation Policies (DIPs) and eliminate the need for callbacks, window.top, window.parent, etc., in preparation for upcoming WordPress changes.
Divi Page Builder
Support for the Divi 5 block has been added, along with backwards compatibility for the legacy Divi 4 block.
Gutenberg
The Gutenberg block has been rebuild using the latest framework.
Breaking changes
We have removed support for legacy versions of Contact Form 7 (versions below V6). Contact Form 7 version 6 and above is supported.
Out-of-the-Box | Best Dropbox Plugin for WP v3.7 Nulled Additional Bug fixes
Fixed an issue with the full-text search where the Box API would only return exact file name matches in the search results when the plugin explicitly requested that all content types be checked.
Out-of-the-Box | Best Dropbox Plugin for WP v3.5.3 Nulled
= 7 April 2026 Bug fixes
Issues with Gutenberg block compatibility have now been resolved.
Fluent Forms
Resolved upload field compatibility for Fluent Forms when the field is used in combination with advanced Fluent Forms logic, such as conditional logic and repeaters.