Skip to content
Back to blog

How to Restrict Your WordPress Forms to Logged in

There are many situations where you only want authenticated visitors to submit a form. Whether you’re running a membership site, client portal, intranet, or a restricted...

Michał Mikołaszek
Michał Mikołaszek
Oct 2, 2026
11 min read
How to Restrict Your WordPress Forms to Logged inContent entirely generated by artificial intelligenceContent entirely generated by artificial intelligenceThis content was entirely generated by artificial intelligence, with no human element (other than the prompt).

There are many situations where you only want authenticated visitors to submit a form. Whether you’re running a membership site, client portal, intranet, or a restricted support channel, limiting access to registered users only helps you control spam, protect sensitive data, and keep your workflows cleaner and more secure.

Why Restrict Forms to Authenticated Users?

Before diving into implementation, it’s important to understand why you might want to limit a form to logged in users only. Some common use cases include:

  • Member dashboards where only subscribers can submit profile changes or account requests.
  • Client portals for project updates, file uploads, or support requests.
  • Internal workflows such as employee request forms or company intranet tools.
  • Premium support where only paying customers can submit tickets.
  • Reducing spam by ensuring all submissions come from verified user accounts.

By restricting your form to authenticated visitors, you gain more control over who can submit data, and you can more reliably associate each entry with a user profile in your WordPress database.

Planning Your Access Rules

Limiting a form to logged in users can be as simple as hiding it from guests, or as advanced as restricting submissions by specific user roles and capabilities. Before implementing any solutions, decide on the following:

  • Who should submit this form? Any logged in user, or just certain roles (e.g., subscribers, customers, editors)?
  • What should guests see? Nothing at all, a simple message, or a login/registration prompt?
  • Do you need role-based logic? For example, staff forms visible only to employees, not regular members.
  • How critical is security? For highly sensitive data, you may want stricter checks and capability-based access.

Once you’ve mapped out who should have access and how you want the fallback experience to look, you can choose the most appropriate method to implement the restriction.

Method 1: Restrict Any Form with a Shortcode Wrapper

If your form is added to a page with a shortcode, you can use a simple login check wrapper so the form only renders when a visitor is authenticated. This is a flexible approach that works with most form plugins, custom forms, and even Gutenberg blocks.

Using a Custom Shortcode

You can create a shortcode that checks if a visitor is authenticated and then conditionally displays its contents. Add the following code to your theme’s functions.php file or, preferably, to a small must-use plugin to keep things update-safe:

<?php
function wp_auth_only_content( $atts, $content = null ) {
    if ( is_user_logged_in() ) {
        return do_shortcode( $content );
    }

    $defaults = array(
        'message' => 'You must be logged in to view this form.',
        'show_login_link' => 'yes',
    );

    $atts = shortcode_atts( $defaults, $atts, 'auth_only' );

    $output = '<p>' . esc_html( $atts['message'] ) . '</p>';

    if ( 'yes' === $atts['show_login_link'] ) {
        $output .= '<p><a href="' . esc_url( wp_login_url( get_permalink() ) ) . '">Log in</a></p>';
    }

    return $output;
}
add_shortcode( 'auth_only', 'wp_auth_only_content' );

Once the shortcode is registered, you can wrap any form shortcode or Gutenberg Shortcode block inside it:

[auth_only message="Please sign in to submit this request."]
    [your_form_shortcode_here]
[/auth_only]

When a user visits the page:

  • If they are logged in, the nested form shortcode is processed and displayed.
  • If they are a guest, the custom message and login link are shown instead.

This method keeps your layout within the editor while still enforcing an authentication check server-side.

Adding Role-Based Conditions

You can extend the shortcode to restrict access to specific user roles by checking the visitor’s capabilities. For instance, to allow only users with a particular role or capability, you can enhance the raw content of the shortcode handler like this:

if ( is_user_logged_in() ) {
    $user = wp_get_current_user();

    if ( in_array( 'subscriber', (array) $user->roles, true ) ) {
        return do_shortcode( $content );
    }
}

Replace the role with whatever user group should have access, such as customer, member, or a custom role from your membership plugin.

Method 2: Using Your Form Plugin’s Built-In Settings

Most modern form plugins for WordPress include an option to limit access to authenticated users. Leveraging built-in settings is usually the easiest and safest way to enforce login-only submissions, especially for site owners who prefer configuration over code.

Gravity Forms

For sites using this plugin, you can control visibility directly from the form settings:

  • Edit your form in the builder.
  • Navigate to the Form Settings panel.
  • Locate the option to require authentication or restrict to certain roles.
  • Configure the message guests should see when they attempt to view the form.

You can also populate hidden fields with the currently logged in user’s data, which is useful for associating each entry with a user account without exposing those fields on the frontend.

WPForms

This plugin offers an authentication-based restriction from its form settings or using conditional logic on entire forms. Common configuration steps include:

  • Open the form builder and go to the appropriate settings tab.
  • Enable an option such as “Require user to be logged in” for submissions.
  • Add a custom message for non-authenticated visitors.

By combining login-only access with field-level conditional logic, you can build complex, role-aware forms that automatically adapt based on who is signed in.

Other Popular Form Plugins

Many other form solutions offer similar options, often under “Permissions,” “Restrictions,” or “Access” settings. Look for features such as:

  • Require authentication for form display or submission.
  • Restrict by user role or capability.
  • Custom messages for guests or unauthorized users.
  • Support for dynamic population of user data fields.

If your plugin does not offer built-in access control, you can usually combine its shortcode with a wrapper method like the one described earlier.

Method 3: Restricting Form Pages with Membership or Security Plugins

Another approach is to protect the entire page or post that contains your form, rather than targeting the form itself. This is particularly effective when you already use a membership, LMS, or security plugin to manage access across your site.

Using Membership or LMS Tools

Many membership plugins and learning management systems provide granular content restriction features. You can typically:

  • Mark a page as “logged in users only.”
  • Restrict content to specific membership levels or course enrollments.
  • Control what guests see, such as an excerpt, a teaser block, or a login/register form.

By placing your form inside a protected page, only authorized members can access it, and you maintain a consistent access model across all protected content.

Using a Security or Access-Control Plugin

Some security and access-control plugins for WordPress let you enforce authentication-based visibility at the post or page level. Typical features include:

  • Options to hide content from guests entirely.
  • Redirection of unauthenticated users to the login page.
  • Support for role-based content visibility.

This approach is easiest when you want to protect more than just a single form — for example, a full private area of your site dedicated to existing clients or staff.

Method 4: Programmatic Checks in Template Files

For more direct control, you can embed your form in a template file and wrap it in an authentication check. This is especially useful for developers working with custom themes or complex layouts.

Checking Login Status in PHP

If your form is output in a PHP template, you can use is_user_logged_in() to decide what to display:

<?php if ( is_user_logged_in() ) : ?>

    <!-- Render your form here -->
    <?php echo do_shortcode( '[your_form_shortcode_here]' ); ?>

<?php else : ?>

    <p>You must be logged in to submit this form.</p>
    <p><a href="<?php echo esc_url( wp_login_url( get_permalink() ) ); ?>">Log in</a></p>

<?php endif; ?>

This server-side check ensures the form is never rendered for guests, even if they try to bypass the frontend or access the page source. You can extend the logic to check specific roles using current_user_can() or by examining the current user object.

Improving the User Experience

When working at template level, you have full control over the user journey:

  • Redirect unauthorized visitors to a dedicated login page with a friendly explanation.
  • Show a registration call-to-action for new users.
  • Display different forms based on user role or membership level.

If you’re building a custom user dashboard or app-like experience, this pattern integrates seamlessly with your routing and layout structure.

Best Practices for Restricted Forms

Restricting forms to authenticated visitors solves a lot of problems, but to get the most from it you should follow a few best practices around security, usability, and performance.

Do Not Rely on Frontend Checks Alone

JavaScript-based checks or simple visual hiding are not sufficient. Always enforce restrictions on the server side using WordPress authentication functions. Otherwise, anyone can still potentially submit data to your form’s processing endpoint directly.

Provide Clear Messaging

When a visitor is not authorized, don’t just hide the form with no explanation. Instead:

  • Explain why access is restricted (e.g., “This form is only available to registered members”).
  • Provide a direct login link, ideally redirecting back to the original page after sign-in.
  • Offer registration or upgrade options where relevant.

Clear messaging reduces confusion and helps legitimate users complete the desired action quickly.

Leverage Logged In User Data

Once a user is authenticated, you can prefill or hide certain form fields based on their profile:

  • Store the user ID as a hidden field for easier tracking in your CRM or automation tools.
  • Automatically populate name and email fields to speed up submission.
  • Apply conditional logic based on user role, membership level, or previous activity.

This not only improves the user experience but also adds valuable context to each entry.

Secure Your Submission Endpoints

Restricting the form’s visibility is one layer of protection. Also ensure that:

  • Submissions are only processed for authenticated users at the server level.
  • Nonces and other anti-CSRF measures are correctly implemented.
  • Fields are validated and sanitized, regardless of who is submitting the form.

These safeguards are essential, especially when handling sensitive information such as account details, internal requests, or private documents.

Testing Your Configuration

After you’ve restricted your form, thoroughly test the experience from multiple perspectives:

  • Guest view: Log out or use an incognito window to confirm the form is not accessible and that your message and login prompts work as intended.
  • Basic user view: Log in with a standard account such as a subscriber or customer and verify that the form is visible and functional.
  • Admin view: Check that administrative accounts continue to see the form and can test submissions for troubleshooting.
  • Role-specific testing: If you are restricting by role, test each relevant user role individually.

Pay attention not only to whether the form appears, but also to redirects, messages, and any automated notifications or workflows that trigger on submission.

Enhancing the Experience with Login and Registration Flows

When you require authentication before submission, make it as easy as possible for users to log in or create an account without losing context.

Smart Redirection

Use login URLs that redirect users back to the originating page after successful authentication. For example, wp_login_url( get_permalink() ) ensures that, after signing in, visitors return directly to the protected form they were trying to access.

Inline Login or Modal Forms

Instead of sending users to a separate login page, you can embed:

  • A compact login form above or below the protected form area.
  • A modal popup triggered when guests click a “Sign in to continue” button.

This keeps the interaction streamlined and reduces the friction between arriving at the page and completing the form.

Connecting Registration with Form Access

If your form is intended for new users, pair it with your registration flow:

  • After user registration, redirect to the page containing the restricted form.
  • Automatically log in the user upon successful registration where appropriate.
  • Display a confirmation message explaining that they now have access to previously restricted forms.

Aligning your registration and form access strategies helps maintain a consistent and intuitive user journey.

Conclusion

Limiting a form to logged in users only is a powerful way to improve data quality, enhance security, and tailor the user experience. Whether you use a shortcode wrapper, built-in features of your form plugin, membership-based content restrictions, or template-level checks, the key is to enforce authentication on the server side while providing a clear and helpful experience for your visitors.

Start by defining who should have access, then choose the method that best fits your stack and skill level. Once in place, your restricted forms will become a reliable part of your authenticated user workflows, supporting everything from simple member feedback to advanced internal processes.

Michał Mikołaszek
Michał Mikołaszek

I’ve been leading Grafiduo since 2010 as the CEO. Together with my development team, I create e-commerce solutions, websites, and digital designs that combine functionality with aesthetics. I focus mainly on WordPress, WooCommerce, and Prestashop, helping businesses grow through well-crafted online experiences.