PublishPress Permissions: Access Control, Content Permissions, User Access
by PublishPress 4.3 (66 reviews)

PublishPress Permissions: Access Control, Content Permissions, User Access

The permissions plugin for posts, pages, categories, tags and more. You can control permissions for roles, individual users, and even custom groups.

PublishPress Permissions ranks #1,594 among WordPress.org plugins with 10,000+ active installations, is #152 of 4,488 in the Security category, a 4.3/5 rating from 66 reviews, and was last updated Sep 8, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v4.8.4 Current Version v4.8.4
Updated 1 week ago Last Update on 08 Sep, 2026
Refreshed 6 hours ago Last Refreshed on
#152 of 4,488 in Security Top 5% by installs Downloads -80.6% this week Actively maintained
View on WordPress.org
Rank
#1,594
-1 this week
Active Installs
10K+
-43.1%
KW Avg Position
10.2
0.2 worse
Downloads
880.9K
+69 today
Support Resolved
100%
No change
Rating
86%
Review 4.3 out of 5
4.3 (66 reviews)

Next Milestone 20K

Total Progress 78.4%
10K+ 20K+
173
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 2,160 more installs to reach 20K+

Rank Changes

1,519 1,561 1,602 1,643 1,685 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
1,594 1,601 1,608 1,614 1,621 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #1,594
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 100 200 300 400 500 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 500 1K 1.5K 2K 2.5K 3K 3.5K 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.3
66 reviews
Overall 86%
5
48 (73%)
4
6 (9%)
3
2 (3%)
2
4 (6%)
1
6 (9%)

Support Threads Overview

Resolved
Unresolved
2
Total Threads
2
Resolved
0
Unresolved
100%
Resolution Rate

Security History

Source: WPVulnerability

1 known vulnerability on record · 1 in the last 24 months · checked 1 week ago

  1. PublishPress Permissions: Control User Access for Posts, Pages, Categories, Tags [press-permit-core] < 4.8.4

    CVE-2026-84771 · Fixed in v4.8.4

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who need to restrict who can view or edit posts, pages, categories, tags, and media files. It solves the problem of controlling content access by user role, individual user, or custom user group, including hiding other users' posts and restricting media library files.

  • Viewing permissions for content
  • Editing permissions for content
  • Media Library access control
  • Hide other users' posts
  • Create custom user groups
  • Teaser previews of restricted content (Pro)
  • Automatic personal posts for users (Pro)
  • Integration with bbPress, BuddyPress, WPML, Relevanssi (Pro)

Frequently Asked Questions

Common questions about PublishPress Permissions: Access Control, Content Permissions, User Access

A large number of WordPress have sites with custom post types. These custom post types often hold sensitive information. In this guide, we'll show you how to control who can read, edit and publish content in your custom post types. By default, nearly all custom post types will inherit the same permissions as Posts. So a user in the “Editor” will role will automatically be able to write and edit in your custom post type. Install the PublishPress Permissions Pro plugin. Go to Permissions > Settings > Core. Under “Filtered Post Types”, check the box for your post type. Click “Save Changes”. You will now be able to edit any post in your custom post type and see editing permissions. Click here to see how to restrict access to custom post types.
Yes, PublishPress Permissions makes it possible to control who can view and read content with a specific category attached. In this situation, “read” means “view”. So we're going to control who can see this content. By default, Categories are only available on WordPress Posts. However, you can add Categories to other post types and so you will be able to use the tutorial for those post types too. Click here to see how to restrict access to categories.
This guide will show you how to require users to create content in a specific category or parent page. The solution in this guide is a flexible approach for sites with a substantial number of users in different roles. Depending on the needs of your site, the PublishPress plugins also offer other approaches such as this one based on user roles. In this tutorial, we'll use examples from a university. Our sample site has categories for different university departments. Our aim will be to restrict some users to posting in some categories, or underneath some parent pages. By default, Categories are only available on WordPress Posts. However, you can add Categories to other post types and so you will be able to use the tutorial for those post types too. Click here to see how to force users to post in a category.
Yes, the PublishPress Permissions plugin allows you to block access to WordPress category and tag archive pages. For example, you can block public access to the “Blog” category on your site. We will use this as an example, but the same approach can work for all taxonomies. Install the PublishPress Permissions plugin. Go to “Posts”, then “Categories”. Click “Edit” for your category. Scroll down to the “Permissions: Read Posts in this Category” area. Set “Anonymous” to “Blocked”. This will impact anyone who is anonymous / not logged in to your site and tries to visit a post with the “Blog” category, or “Blog” category archive page. People without access to this category will only see a “Page Not Found” message. Click here to see how to deny access to blog archives.
The PublishPress Permissions plugin allows you to control permissions for media files on your site. Go to Permissions > Settings. Click the “Core” tab and make sure the “Media” box is checked. Click the “Editing” tab. Scroll down to the “Media Library” area. Here you're going to see 4 options you can use to control access to files inside the Media Library: List other users' uploads if attached to a readable post: If this boxed is checked, users can view other people's media files if they are attached a post they can read. List other users' uploads if attached to an editable post: If this boxed is checked, users can view other people's media files if they are attached a post they can edit. Edit other user' uploads if attached to an editable post: If this boxed is checked, users can edit other people's media files if they are attached a post they can edit. Other users' unattached uploads listed by default: If this boxed is checked, users can view other people's media files. Click here to see how to control access to the Media Library.
By default, all the files and images you upload to WordPress are publicly available. This is great news for most sites. The goal of most sites is to create popular content that is viewed by as many readers as possible. But this public access is a problem if you run a membership site and DO NOT want everyone reading your content. Yes, you can restrict the privacy of your posts, but people can still view your files if they know the URL. The PublishPress Permissions Pro plugin makes it possible to block direct access to your media files. Even if someone knows the URL, they won't be able to access your files unless you give them the correct access. Click here to see how to block people and search engines from accessing file URLs.
By default, WordPress only allows Administrators to create users. If you want to allow other roles to create users then you need to give them at least the promote_users, list_users, edit_users and create_users permissions. However, if you give them those permissions, they can create and edit users in any role. So you could have Editors creating and editing Administrator accounts. That could be a security problem. Fortunately, PublishPress Permissions has a feature called “Limit User Edit by Level”. This prevents anyone from editing a user with a higher level or assigning a role higher than their own. Click here to see how to restrict user creation.
PublishPress Permissions can be used in addition to a basic role editor / user management plugin. Those plugins are designed to modify existing WordPress permissions. That's a valuable task, and in many cases will be all the role customization you need. We do recommend PublishPress Capabilities which is a WordPress role editor designed for integration with PublishPress Permissions. PublishPress Permissions can supercharge your permissions engine and goes much further than the basic role editor plugins. PublishPress Permissions is particularly useful when you want to customize access to a specific post, category or term. PublishPress Permissions adds content-specific editing permissions, custom post status permissions, file access restriction, and other features which are not possible in default WordPress.
Moving forward, we do not plan any major development of the Role Scoper code base. If you encounter issues with Role Scoper and need to migrate to a different solution, PublishPress Permissions provides access to an import script which can automate the majority of your Role Scoper migration. PublishPress Permissions can import the most Role Scoper groups, roles, restrictions and options. Some manual follow up may be required for some configurations.
No, but it can potentially be used in conjunction with an e-commerce or membership plugin. If you have a way to sell users into a WordPress role or BuddyPress group, PublishPress Permissions can grant access based on that membership.

More plugins by PublishPress

Sign In / Register

You need to sign in or register to use this feature.