DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Formidable Forms

How to Restrict WordPress Forms to Logged-In Users

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restrict access on the form itself, not merely on the page that contains it. Open your form plugin’s settings, enable its logged-in-only or role-visibility option, and give logged-out visitors a clear login or registration message. The exact path depends on whether you use Gravity Forms, WPForms, Formidable Forms, or another plugin.

Choose the restriction that matches your form plugin

Plugin Setting and path What guests see Plan or version notes
Gravity Forms Form Settings → Restrictions → enable Require user to be logged in. A customizable require-login message; Gravity Forms supports HTML and shortcodes in that message. See the official Gravity Forms instructions. The gform_require_login filter, including form-specific variants such as gform_require_login_6, is documented as available from Gravity Forms 2.4. See the filter documentation.
WPForms Open the form, then Form Locker → Form Restrictions, and enable Logged in users only. Enter the visitor message. Follow the Form Locker setup guide. Your custom message for visitors who are not logged in, with links to log in or register if appropriate. WPForms’ guide updated April 19, 2026, says Form Locker is available on Pro and higher plans. Confirm the current entitlement and plan names before publishing; see the WPForms access guide.
Formidable Forms Use the premium Limit form visibility control and select the user roles allowed to see and submit the form. See Formidable’s form-settings documentation. Users outside the selected roles cannot use the form; configure the visibility message or surrounding page content to explain the next step. Role-based visibility is a premium feature. An unpublished form can still be reachable through its preview URL, so do not treat “unpublished” as an access control.

Configure the guest experience

A restriction that only hides a form can leave visitors confused. Make the message explain why access is limited and provide the correct route:

  • Link to the site’s login page.
  • Link to registration when new accounts are allowed.
  • Explain which account or role is required, such as “members” or “staff.”
  • Tell users what to do after registering or requesting access.

For a site-wide or programmatic Gravity Forms rule, use the documented gform_require_login filter, or a form-specific hook such as gform_require_login_6. Apply code only after confirming the form ID and the plugin version in use; a settings-based restriction is easier for non-developers to maintain.

Do not confuse page protection with form protection

Putting a form on a members-only page is not always equivalent to enabling the form’s own access control. A form may be embedded elsewhere, rendered by a shortcode, or exposed through a preview URL. Set the restriction in the form plugin and review every place the form is embedded.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Formidable specifically warns that an unpublished form may remain accessible through its preview URL. Use its visibility setting when unauthorized viewing or submission matters.

Protect uploaded files separately

Login-only form access does not automatically prove that uploaded files are protected. If the form accepts documents, inspect the plugin’s file-access controls and test both entry-linked and direct file URLs. WPForms documents separate restrictions for logged-in users, roles, and individual users, including files reached through entries or direct links. Configure those controls independently from the form’s visibility setting.

Exclude the restricted page from caching

Login-required forms can fail when a cache serves an old copy. Gravity Forms says pages requiring login should not be cached because its form nonces refresh every 12 hours; a stale cached form can produce submission errors. Exclude the form page from page and edge caching in your actual cache stack, then clear existing cache entries and retest.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Understand what login restriction does—and does not—secure

Requiring an account is an access gate, not encryption. Gravity Forms’ security guidance states that entries are not encrypted and advises against storing highly sensitive information such as passwords or credit-card details. Use appropriate data-handling, retention, and payment controls for sensitive fields; do not rely on a login requirement as a substitute.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify both visitor states

  1. Open the form page in a private or logged-out browser window. Confirm that the form is replaced by the intended login or registration message.
  2. Sign in with an account that should be allowed. Confirm that the form appears and that the account can submit it.
  3. If access is role-based, repeat the check with an account outside the permitted role.
  4. If uploads are enabled, test an entry-linked file URL and a direct file URL while logged out and while signed in.
  5. Repeat after purging the site’s caches to catch stale-page or nonce problems.

Which approach should you use?

Need Best fit
You already use Gravity Forms and need a simple login gate Enable Require user to be logged in in Restrictions.
You already use WPForms and want a guided restriction message Use Form Locker’s Logged in users only option, subject to the current plan requirement.
Different membership levels need different access Use Formidable’s role-based visibility, or the equivalent role control in your installed plugin.
The form collects uploads Configure the plugin’s separate file-access restrictions as well as the form gate.
The form page is cached Add a cache exclusion before launch and validate it with logged-out and logged-in tests.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.