How to restrict WordPress media files access to specific user roles

September 9, 2021

If you’re running an online business selling courses or information products, you’ll want to build some private areas where only your customers or subscribers can access premium content and digital product files. Password and membership protection prove useful in these cases.

However, there is a serious loophole in these protection methods that often result in your digital product files being leaked out.

In this article, we’re going to show you the right way to protect both your WordPress content and digital products without any technical knowledge.

Why you should protect WordPress media files

Did you know that even though your website content is protected with a password or membership plugin, the media attachments embedded in those pages are still accessible to anyone who has direct links to those files?

Restrict WordPress Media Files

That's because password and membership plugins don’t protect your file uploads - they're designed to protect content instead, such as pages, posts or products. As a consequence, if someone shares these file URLs on other forums and social platforms, others will be able to access them without having to purchase membership or log into your website.

Even worse, these private documents, videos, and images - just like your content - could be indexed by Google or other search engines. So people can just find and access them directly through some simple search with the right keywords.

If you're selling courses or digital products then this puts you at risk of losing all your efforts, digital product files, and a lot of money...

How to protect WordPress media attachments

The Prevent Direct Access (PDA) Gold plugin provides many different ways to protect your WordPress media files. You can protect new file uploads automatically or on the fly under the WordPress media library. Alternatively, you can protect some specific files when editing a page or post. Instead of protecting each file individually, you can select and protect multiple files simultaneously using WordPress bulk actions under Media list view.

Protect WordPress files

Most importantly, PDA Gold enables you to protect your media files to specific user roles. That’s when “File Access Permission” comes into play.

File Access Permission

File access permission
File Access Permission (FAP) allows you to select certain user roles who can access your private protected files directly. There is global FAP which applies the permissions to all files by default. What’s more, you can set individual FAP with Access Restriction extension. In other words, different files can be made accessible to different user roles.

While most of the options are self-explanatory, you may wonder when to use the "Anyone" and "No one" options:

  • Anyone option allows everyone to access your private files while stopping Google or other search engines from indexing them. This comes in useful when you want those files to be directly accessed through your website links and not through search results.
  • No one option literally stops everyone from accessing your protected files directly through their file URLs. In return, PDA Gold plugin gives you the power to create as many private download links as needed. This helps you share your protected files with some specific groups of users. And at the same time, you can track and restrict its usage by time or click.

How to protect both WordPress content and file attachments

The most bulletproof way to secure your WordPress content is to protect both your content and media attachments altogether.

Password Protected Categories - and it's e-commerce version WooCommerce Protected Categories - is one of the best WordPress password protection plugins. Both plugins allow you to protect an entire category including its sub-categories and all posts/products under that category, with a single password. You can also restrict entire categories so that they're only visible to specific logged-in users or roles.

Now, let’s learn how to integrate Prevent Direct Access Gold with Password Protected Categories and WooCommerce Protected Categories. It's the perfect combination to protect both WordPress categories and media file attachments on these posts/products.

Using Prevent Direct Access with WooCommerce Protected Categories

Follow these simple steps to protect any type of WordPress category. This could be a post category, page category, WooCommerce product category, or a category/custom taxonomy for any other custom post type.

You can protect as many categories as you’d like to while leaving the rest accessible to the public:

  1. Visibility options in WooCommerce Protected Categories plugin.
    Go to the 'Add/Edit Category' page.
  2. Add a new category or edit an existing one.
  3. Under the ‘Visibility’ section above the ‘Add New Category’ button, select ‘Protected’.
  4. Set a password and/or select user roles or specific users who can access the post/product.
  5. In the WordPress Media Library List view, protect your attachment file and then click on ‘Configure File Protection’.
  6. Select the ‘File Access Permission’ tab and choose the same user roles as per step 4.

Where to get the plugins

Password Protected Categories and WooCommerce Protected Categories are the top WordPress security plugins. They work seamlessly with Prevent Direct Access Gold. It's the perfect way to protect both your content and WordPress private files to specific user roles.

Now, you can not only protect your private attachment files against Google and unwanted users. Simply by logging into their user account, your visitors can unlock both your attachments and protected media library files, as well as content.

Create hidden areas for your WordPress blog posts, portfolios, courses & more.
Start hiding areas of your WooCommerce store today.

Do you have any questions on how to password protect your website content and attachment files in WordPress? Please let us know in the comments section below.


  1. John
    February 6, 2021 Reply

    I want to offer certain products (video downloads) to specific users as it will have their branding, can i have a login page as the homepage? Also do you allow videos on product pages? is there a theme you could recommend for this.

    • Edge
      February 9, 2021 Reply

      Hi, John. Thanks for your interest in WooCommerce Protected Categories.

      You can create a login form customized for each user's or user role's branding via the Theme My Login plugin, as discussed in our article: User and role protected categories.

      Yes, in WooCommerce you can embed videos in the product description field, which will display in the single product pages.

      Our plugins have been coded to work with any theme, and I recommend those that are fully WooCommerce-compatible, such as the default Storefront theme by Automattic, and the Boutique and Deli themes by WooCommerce. We also mention other themes at (albeit the article is about another plugin of ours, these should also work well with WooCommerce Protected Categories).

  2. Cassandra Maccue
    April 14, 2019 Reply

    Great tips, Thank you kindly. Do you have a video available for these tips?

    • Katie Keith
      April 15, 2019 Reply

      Hi Cassandra, we don't have a video for this tutorial yet and hope to add one in future. Thanks for the suggestion!

      • Cassandra Maccue
        April 20, 2019 Reply

        I look forward to it eagerly. Thank you once again.

Please share your thoughts...

Your email address will not be published.