Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To let a WordPress Contributor edit an already-published post without giving them the power to publish changes, grant a controlled contributor role the edit_published_posts capability and leave publish_posts disabled. Keep editorial review in place: permission to save an edit does not automatically make every later change wait for approval.

Why the default Contributor role cannot edit an approved post

WordPress describes a Contributor as someone who can write and manage their own posts but cannot publish them. The default Contributor role does not include edit_published_posts, the capability WordPress uses to allow a user to edit their own published posts. See WordPress roles and capabilities.

That distinction matters after approval: once an editor publishes a Contributor’s draft, the post is published, and the default role no longer has the capability needed to edit it. Adding that capability can enable edits while preserving the separate restriction on publishing.

Choose how to grant the permission

There are three practical approaches. Whichever you choose, grant only the permissions contributors need, preserve editorial control of publishing, and test the result with a non-administrator account. The available guidance names WPCode and PublishPress, but does not establish their compatibility with every current WordPress release or their current commercial terms; check each product’s current documentation before deploying it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Approach Setup and scope Publishing and review Maintenance and support
Contributor-derived role with a capability change Requires changing role capabilities, typically with code. Configure the role so contributors can edit their own published posts, not other users’ posts. Keep publish_posts off the contributor role. Editors or administrators retain publishing authority. Revisions remain the way to compare and restore saved versions. Requires someone to maintain and verify the role change as the site and WordPress version change. Vendor support is not stated; support depends on who implements it.
WPCode snippet Uses a code snippet to add the capability. Scope still needs to be restricted to contributors’ own posts and verified on the site. A snippet adding edit_published_posts should not also grant publish_posts; confirm the permissions actually assigned. It does not itself create approval for every edit. Verify the snippet against the current WordPress version and test before use. Compatibility and vendor support are not stated in the cited implementation guidance.
PublishPress permissions Uses a plugin interface to change role permissions. Select a role or permission scope that limits editing to the contributor’s own posts. Leave publication rights with editors if changes must be approved. Check that the chosen settings do not let contributors publish. Check the plugin’s current settings, compatibility, and support terms before deployment; these details are not established here.

Native role-capability change

A dedicated role derived from Contributor is the clearest way to separate “can edit an approved post” from “can publish.” Add edit_published_posts to that role, and do not add publish_posts. Avoid broadening the built-in Contributor role if only a subset of contributors should receive this permission; a separate role makes the difference easier to manage.

WPCode

WPCode is an option for adding the capability through a snippet rather than editing theme files. Use a snippet only after checking what role and posts it affects. Test with a non-admin account, because an administrator’s broad permissions can hide a misconfiguration.

PublishPress

PublishPress is an option for managing permissions through a plugin. Configure a role or permission scope for contributors’ own posts, and verify that it leaves publication rights with the editorial role. Plugin settings and compatibility can change, so use the current product documentation for the installed version.

How to preserve editorial approval

Granting edit access is not the same as requiring approval for every edit. The capability can let a contributor save changes to an already-published post; do not assume those saved changes will automatically enter an editor approval queue. WordPress’s capability checks govern whether a user may perform an action on a particular post, while your editorial workflow determines who reviews changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a review-before-publication workflow, leave publish_posts disabled for contributors. Ask contributors to submit edits for an editor to review, and have an editor publish the accepted change. WordPress checks permissions for the specific post; its developer reference illustrates this with current_user_can( 'edit_post', $post_id ). See the current_user_can() developer reference.

Use WordPress revisions to inspect saved drafts or published updates and restore an earlier version if needed. Revisions help with comparison and recovery; they do not replace an approval process or limit who can save an edit. The WordPress workflow discussion covers revisions and permissions in editorial workflows: WordPress post revisions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test the permissions before enabling them for contributors

Test in a staging environment with a non-admin account assigned the modified role. Confirm each of these behaviors:

  • The contributor can edit and save their own published post.
  • The contributor cannot edit another user’s post.
  • The contributor cannot publish a post or publish an edit.
  • An editor can review and publish the contributor’s proposed change.
  • An editor can inspect revisions and restore an earlier version.

If any test fails, revise the role or plugin scope before applying the change on the live site. In particular, verify both sides of the permission boundary: access to the contributor’s own published posts and no unintended access to other posts or publishing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.