Free tools Windows power users keep installed
One-click scans. No signup required.
To restrict the attachments returned in WordPress’s editor media modal, filter ajax_query_attachments_args and set the query’s author to the logged-in user’s ID. This limits which attachment records that query returns; it does not, by itself, make file URLs private or secure every other way of accessing media.
How WordPress identifies a user’s uploads
WordPress stores media items as attachment posts and records the uploader as the attachment author. Its documentation notes that “Media items are also ‘Posts’ in their own right and can be displayed as such via the WordPress Template Hierarchy.” That author field is what lets an attachment query be limited to one user.
Upload permission and access to existing attachments are separate concerns. The upload_files capability grants access to Media and Media > Add New; it does not itself specify that users can see only their own files. In WordPress’s documented default roles, Authors have upload_files, while Contributors and Subscribers do not. Administrators and Editors also have it. Site owners and plugins can customize these role capabilities.
Restrict the editor media modal with a query filter
WordPress provides the ajax_query_attachments_args filter for changing the query arguments used to fetch attachments for the editor’s media modal. Set the query’s author argument to the current user ID for the roles you want to restrict. The callback must return the modified query array; otherwise, the modal may show no attachments.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
For example, a site-specific snippet can follow this pattern:
add_filter( 'ajax_query_attachments_args', 'itechguides_filter_attachments_by_author' );
function itechguides_filter_attachments_by_author( $query ) {
$user_id = get_current_user_id();
// Add site-specific role or capability checks here if needed.
if ( $user_id ) {
$query['author'] = $user_id;
}
return $query;
}
This example applies the filter to every logged-in user whose media query reaches the hook. If administrators, editors, or another group should see all attachments, add a bypass based on the site’s actual role policy rather than assuming one capability test fits every setup. Have a developer review and deploy the code through the site’s normal maintenance process.
Rank #2
Check the Media Library list and grid views separately
The Media Library’s list-screen query has a “mine” path: WordPress’s wp_edit_attachments_query_vars() sets the attachment author to the current user when that filter is active. That documents how the query works, but it does not mean every user’s list is automatically restricted to their own uploads. Test the list view and grid view on the target site, as well as the editor media modal.
Choose a snippet or a plugin based on scope
| Approach | Best fit | What to verify |
|---|---|---|
| Custom query-filter callback | You need a narrowly defined rule and can maintain site-specific code. | Which roles or capabilities are restricted; whether the rule covers the modal, list/grid screens, and any custom integrations the site uses. |
| Plugin | You prefer configuration over maintaining a snippet. | Current maintenance status, tested WordPress version, custom-role behavior, and coverage of each interface or API you rely on. A WordPress.org support excerpt describes a plugin intended to limit Authors, Contributors, and roles unable to edit other users’ posts to their own uploads, but that description is not a current compatibility audit. |
WordPress roles are collections of capabilities, and capabilities can be assigned or removed. If a custom role also needs permission to upload files, role-management tooling may help with that separate task; granting upload_files is not an ownership filter.
Rank #3
Know what this restriction does—and does not—secure
A query filter controls which attachment records a particular interface query returns. The documented modal hook does not establish that the underlying file URL becomes private, or that every REST request, plugin screen, custom integration, or direct file request is blocked. If the requirement is confidentiality, assess file serving and API access separately; hiding attachments in the Media Library is not complete file-access security.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

