Free tools Windows power users keep installed
One-click scans. No signup required.
To show users only the files they uploaded, filter attachment queries by the logged-in user’s ID. For the editor’s Media modal, WordPress provides the ajax_query_attachments_args filter; set its author query argument to the current user. Treat this separately from upload permission and from file privacy: a filtered library does not automatically secure every URL, API, plugin screen, or download endpoint.
How WordPress identifies a user’s uploads
WordPress stores each Media Library item as an attachment post. The uploader is recorded as that attachment’s author. WordPress documentation describes media items as “Posts” in their own right, which is why normal post-query arguments such as author can identify ownership.
The restriction therefore works by changing the attachment query, not by moving files or changing the WordPress uploads directory.
Upload permission and visibility are different controls
The upload_files capability grants access to Media and Media > Add New. It does not, by itself, say that a user will see only their existing attachments.
#1 Best Overall
| Default role | Documented upload capability | What that means here |
|---|---|---|
| Administrator | upload_files |
Can upload; visibility still depends on your filtering policy. |
| Editor | upload_files |
Can upload; visibility still depends on your filtering policy. |
| Author | upload_files |
Can upload; add an ownership filter if the library must show only that author’s files. |
| Contributor | Not included in the documented default | Needs the capability granted before the user can upload through the normal Media interface. |
| Subscriber | Only read in the documented default |
Cannot upload unless capabilities are customized. |
Roles are collections of capabilities, and plugins or administrators can change these defaults. Granting upload_files to a custom role solves permission to upload; it does not create an ownership filter.
Restrict the editor’s Media modal with the supported filter
The editor’s media modal uses ajax_query_attachments_args. Its callback receives the attachment query arguments and must return the array. If the callback fails to return that array, the modal can show no attachments.
Rank #2
Basic owner-only callback
<?php
add_filter( 'ajax_query_attachments_args', function ( $query ) {
$user_id = get_current_user_id();
if ( $user_id > 0 ) {
$query['author'] = $user_id;
}
return $query;
} );
Place the snippet in a site-specific plugin or an appropriate theme customization that you maintain. The callback obtains the authenticated user ID and adds it as the attachment query’s author argument.
Decide who should be restricted
Do not assume that every role should receive the same rule. Many sites let administrators or editors manage all media while restricting authors or selected custom roles. Add your own capability or role test before setting author, based on the policy you actually want. For example, a site might bypass the restriction for users with a media-management capability and apply it to everyone else who can upload. The correct capability is site-specific; verify it in the target role configuration rather than copying a blanket administrator check.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
Example with a policy-specific bypass
<?php
add_filter( 'ajax_query_attachments_args', function ( $query ) {
$user_id = get_current_user_id();
// Replace this capability with the one your site uses for unrestricted media management.
if ( $user_id > 0 && ! current_user_can( 'manage_options' ) ) {
$query['author'] = $user_id;
}
return $query;
} );
manage_options is only an example policy check, not a universal recommendation. A custom role may require a different capability, and some sites should restrict users who have that capability for other reasons.
What happens on the Media Library list and grid screens
The standard Media Library list query has a “mine” path. WordPress core’s wp_edit_attachments_query_vars() sets the query’s author argument to the current user when that filter is active. That documents the same ownership mechanism, but it does not mean every user’s list is automatically locked to “mine.”
Rank #4
After adding a modal filter, test both views separately:
- Open Media > Library in list view and check whether the user can switch to an all-media view.
- Open the grid view and confirm that results match the intended owner rule.
- Insert media from the block or classic editor and verify the modal shows the same set.
- Test a user with no uploads; an empty result should be expected, not treated as an error.
If the list or grid remains broader than intended, its query path may need a separate implementation. The modal hook is documented for the modal query; it is not evidence that one callback governs every WordPress screen.
Best Value
Check integrations beyond the core interface
Custom dashboards, page builders, frontend upload forms, REST requests, and other plugins may build their own attachment queries. A rule that works in the editor modal may not affect those requests. Inventory every interface that can search, select, edit, or delete media and verify the owner condition in each one.
- Custom admin screens: inspect their attachment query arguments and add an equivalent author restriction where supported.
- Frontend forms: verify that both the selection list and the edit/delete action enforce ownership.
- REST or AJAX endpoints: check the endpoint’s authorization and query behavior independently.
- Bulk tools: ensure users cannot select another user’s attachment through a separate management screen.
Why this is not complete file privacy
An attachment query controls which records an interface returns. It does not, by itself, make the underlying file URL private or block every route that can expose attachment metadata. Files in a normal uploads directory may remain directly addressable if someone knows the URL, and another endpoint may still reveal an attachment.
If confidentiality is the requirement, separately assess the site’s file-serving, authentication, caching, REST, and plugin access model. Describe the Media Library rule as interface filtering unless those other layers have also been secured.
Custom code or a plugin?
| Approach | Best fit | Questions to verify |
|---|---|---|
| Small custom callback | You need a focused rule for the editor modal and can maintain code. | Which roles are restricted? Are list/grid screens and integrations covered? Who tests changes after WordPress updates? |
| Configuration plugin | You prefer an administrative interface or need broader role-based controls. | Is the plugin actively maintained? Which WordPress version is tested? Does it support custom roles, modal and list/grid views, REST requests, and your required security scope? |
A WordPress.org support excerpt describes a plugin intended to limit Authors, Contributors, and roles unable to edit other users’ posts to their own uploads. That description is not a current compatibility or maintenance audit, so verify the plugin’s present listing, tested WordPress version, custom-role behavior, and update history before installing it.
Recommended Free Tools
Quick Recap
A practical verification checklist
- Confirm the target role has
upload_filesif it must upload. - Define whether the rule applies to every non-privileged uploader, selected roles, or a capability-defined group.
- Add the
ajax_query_attachments_argscallback and always return the query array. - Test the editor modal with a user who owns files and one who owns none.
- Test Media Library list and grid views, including any “mine” control.
- Test custom screens, plugins, REST or AJAX integrations, and bulk actions.
- Decide separately whether direct file URLs and attachment metadata require access controls beyond query filtering.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

