Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The safest way to let visitors submit WordPress posts is to use a frontend submission form that saves every entry as Draft or Pending Review. An editor then checks the text, author details, links, images and formatting before publishing. The form handles data collection; WordPress roles and capabilities determine what each person is allowed to do.

Choose the right submission workflow

Decide first who may submit and what happens after they click Submit.

  • Guests: submit without a WordPress account or wp-admin access.
  • Logged-in members: submissions can be attributed to the current user.
  • Moderated publishing: every post enters Draft or Pending Review.
  • Automatic publishing: use only for trusted users who have the publish_posts capability.

For public forms, Draft or Pending Review should be the default. Publishing directly makes spam, malicious links and unsuitable media visible immediately.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand WordPress roles and capabilities

WordPress includes Super Admin, Administrator, Editor, Author, Contributor and Subscriber roles. Roles contain capabilities such as edit_posts, publish_posts and upload_files.

A frontend form does not replace authorization. Any plugin or custom integration that accepts or edits data must check the user’s capabilities. Do not give untrusted contributors publish_posts or unfiltered_html; the latter can allow unsafe or badly formatted code.

Option 1: WPForms Post Submissions

WPForms’ Post Submissions addon creates posts from a frontend form, so guests can submit without dashboard access. The addon requires a Pro license or higher.

What you can collect

  • Post title and content
  • Featured image
  • Excerpt and category
  • Author name and email

Map each form field to the corresponding WordPress post field, then set the resulting post status to Draft or Pending Review. Logged-in submissions can be assigned to the current user.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Important editing limitation

WPForms documents that submitters cannot update a post after submission unless they have dashboard access. Giving a contributor or author an appropriate role is one possible solution, but it also changes that user’s WordPress permissions.

Option 2: User Submitted Posts

User Submitted Posts adds a shortcode-based frontend form. Insert [user-submitted-posts] into a post, page or widget.

Built-in controls

  • Name, email, URL, title, tags, category and content fields
  • Custom fields and terms-agreement fields
  • Image uploads and featured-image handling
  • Challenge questions, reCAPTCHA and Cloudflare Turnstile
  • Optional login requirements and email notifications

The plugin can create Draft, Pending or Published posts, and it can be configured to publish only after a specified number of submissions. For a guest-post site that wants many controls in one focused form, this is a practical option; use Draft or Pending while establishing your moderation process.

Option 3: Formidable Forms

Formidable Forms can turn form entries into WordPress posts, pages or custom post types. Add a post-status field so an administrator can move an entry from Draft to Published.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frontend approval and editing

Its documented frontend pattern displays only draft entries in a View and provides an update link that changes the status to Published. The frontend editing feature is premium. Site owners can let logged-in users edit their own submissions, allow administrators to edit other users’ entries and set permissions by role.

This is the clearest fit when contributors need to revise their own posts after submission without receiving broad wp-admin access. Decide whether an edit sends the post back to Pending Review; otherwise an approved post could change without a second editorial check.

Set up a moderated submission form

  1. Choose the audience. Allow guests, logged-in users or both.
  2. Create the fields. At minimum collect a title, body, author name and email. Add category, excerpt, featured image or custom fields only when editors will use them.
  3. Set the initial status. Choose Draft or Pending Review rather than Publish.
  4. Set attribution. Use the logged-in account when available, or store guest author details in the fields your workflow requires.
  5. Configure notifications. Notify the editorial team when a submission arrives; do not treat an email notification as approval.
  6. Protect the endpoint. Enable CAPTCHA or Turnstile, validation, rate limiting and hidden-field or challenge-question checks where available.
  7. Restrict uploads. Allow only required image types and sizes, and inspect files before publication.
  8. Test as each audience. Submit while logged out, while logged in as a low-privilege user and as an administrator. Confirm that status, attribution, notifications and edit permissions match the policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Moderation and security checklist

  • Check capabilities on every submission, update and status-change action.
  • Keep untrusted users away from publish_posts and unfiltered_html.
  • Validate titles, content, email addresses, URLs, categories and custom fields.
  • Use CAPTCHA or Turnstile, rate limits and notifications for public forms.
  • Limit upload MIME types, dimensions and file sizes; review images and links manually.
  • Record who submitted a post and who approved it.
  • Define whether contributor edits require re-approval.
  • Remove or quarantine spam and suspicious links before publishing.

Which approach should you use?

Requirement WPForms Post Submissions User Submitted Posts Formidable Forms
Guest submissions Yes Yes, with optional login requirement Yes, depending on form permissions
Draft or Pending workflow Yes Yes Yes
Direct publishing controls Status is configurable Draft, Pending, Publish or conditional publishing Status field and approval workflow
Frontend editing by contributors Not after submission without dashboard access Not established in the documented feature summary Yes; premium feature with role-based permissions
Custom post types Not stated Custom fields supported Yes
Media uploads Featured-image field Image uploads and featured-image handling Depends on the form configuration
Spam controls Use the form’s available protection features reCAPTCHA, Turnstile, challenge questions and hidden-field validation Configure validation and available anti-spam protections
Dashboard exposure Designed for frontend submission Shortcode-based frontend form Frontend forms and views
Premium requirement Pro license or higher for the Post Submissions addon Not stated Frontend editing is premium

How to handle contributor revisions

There are two separate permissions: editing a submitted post and changing its publication status. A contributor may need edit_posts without publish_posts. If the site permits frontend revisions, require login, restrict users to their own entries and send every changed post back to Pending Review. Administrators or editors can then approve the revision.

For occasional guest submissions, keep the process one-way: collect the post, ask for revisions by email or another controlled channel, and let an editor update the WordPress entry. Do not create accounts solely to solve an editing requirement unless the site’s permission model has been reviewed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.