Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To restrict a WordPress form to logged-in visitors, enable the login-only or role-visibility option in the plugin that creates the form. Gravity Forms has a built-in login requirement; WPForms provides the option through Form Locker; Formidable Forms offers visibility controls by user role. Set a clear message for guests, then check that uploads and caching are handled separately.

Choose the restriction in your form plugin

First identify which plugin renders the form. The settings differ by plugin, so restricting a page or leaving a form unpublished is not a reliable substitute for the form’s own access control.

Gravity Forms

  1. In WordPress, open the form’s settings and select Restrictions.
  2. Enable Require user to be logged in.
  3. Customize the message shown to logged-out visitors. Gravity Forms supports HTML and shortcodes in this message, so you can provide a login or registration route.

Gravity Forms documents this setting in its instructions for restricting forms to logged-in users. For developers who need a code-based rule, it also documents the gform_require_login filter and form-specific variants such as gform_require_login_6; the filter was added in Gravity Forms v2.4. See the Gravity Forms restriction documentation for the supported approach.

WPForms

  1. Open the form’s settings and go to Form Locker restrictions.
  2. Enable Logged in users only.
  3. Enter the message guests should see, including a suitable login or registration path.

WPForms documents this option in its Form Locker guide. Its setup guide, updated April 19, 2026, says Form Locker is available on Pro and above plans; check the vendor’s current plan names and entitlements before relying on that availability. See the WPForms logged-in access guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Formidable Forms

Use the premium Limit form visibility control to choose which user roles can see and submit the form. Formidable Forms warns that an unpublished form may still be accessible through its preview URL, so use its visibility setting when unauthorized access or submission is a concern. See its general form settings documentation.

Check uploads and other access paths separately

A form’s login gate does not necessarily protect files that have already been uploaded or linked directly. If the form accepts uploads, review the plugin’s file-access controls independently. WPForms documents restrictions for logged-in users, roles, and individual users, including protection for files reached through entries or direct links. See WPForms’ Form Locker and file-access documentation.

Check caching on the restricted page

Gravity Forms advises against caching pages that require login: its form nonces refresh every 12 hours, and a stale cached form can cause submission failures. Exclude the restricted page from caching as appropriate for your cache setup, then validate that the form both loads and submits correctly. Gravity Forms explains the concern in its Security Best Practices.

Verify what guests and members can do

  1. Open the form page in a private browser window or another session where you are logged out. Confirm that the form is not shown and the guest message is useful.
  2. Sign in with an account that should have access. Confirm that the form appears and can be submitted.
  3. If access is role-based, repeat the check with an account in each relevant role.
  4. If the form accepts uploads, check that an unauthorized visitor cannot open uploaded files using their direct URLs.
  5. If the page is cached, test after the relevant cache is cleared and under the site’s normal caching behavior.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Login restriction is not data encryption

Requiring a login controls who can reach a form; it does not encrypt stored entries. Gravity Forms states that entry data is not encrypted and advises against storing highly sensitive information such as passwords or credit card details. Treat the form’s access setting and the site’s data-handling safeguards as separate controls. See Gravity Forms Security Best Practices.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.