WP-Members Membership Plugin

WP-Members Membership Plugin

wp-members
Releases32
Frequency1 month 2 weeks
Last Release
Downloads4.01M

The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.

Membership Sites. Simplified.

You need a membership site, but you want to focus on your business, not mastering a plugin. WP-Members is simple to use, easy to set up, yet flexible in every way imaginable.

Simple to install and configure – yet customizable and scalable!

Features:

WP-Members allows you to restrict content as restricted or hidden, limiting access to registered users.

A full Users Guide is available here. The guide outlines the installation process, and also documents how to use all of the settings.

Support

There is freely available documentation on the plugin’s support site. Your question may be answered there. If you need assistance configuring the plugin or have questions on how to implement or customize features, premium support is available.

You can get priority support along with all of the plugin’s premium extensions in one cost saving Pro Bundle!

Premium Support

Premium support subscribers have access to priority email support, examples, tutorials, and code snippets that will help you extend and customize the base plugin using the plugin’s framework. Visit the site for more info.

Free Extensions

Premium Extensions

The plugin has several premium extensions for additional functionality. You can purchase any of them individually, or get them all for a significant discount in the Pro Bundle.

  • Advanced Options – adds additional settings to WP-Members for redirecting core WP created URLs, redirecting restricted content, hiding the WP toolbar, and more! Also includes integrations with popular plugins like WooCommerce, BuddyPress, bbPress, ADF, Easy Digital Downloads, and The Events Calendar.
  • Download Protect – Allows you to restrict access to specific files, requiring the user to be logged in to access.
  • Invite Codes – set up invitation codes to restrict registration to only those with a valide invite code.
  • MailChimp Integration – add MailChimp list subscription to your registation form.
  • Memberships for WooCommerce – Sell memberships through WooCommerce.
  • PayPal Subscriptions – Sell restricted content access through PayPal.
  • Security – adds a number of security features to the plugin such as preventing concurrent logins, registration form honey pot (spam blocker), require passwords be changed on first use, require passwords to be changed after defined period of time, require strong passwords, block registration by IP and email, restrict specified usernames from being registered.
  • Text Editor – Adds an editor to the WP-Members admin panel to easily customize all user facing strings in the plugin.
  • User List – Display lists of users on your site. Great for creating user directories with detailed and customizable profiles.
  • User Tracking – Track what pages logged in users are visting and when.
  • WordPass Pro – Change your random password generator from gibberish to word-based passwords (can be used with or without WP-Members).

Get support along with all of the plugin’s premium extensions in one cost saving Pro Bundle!

CVE History

CVEPublishedCVSS v3CVSS v2
6.4 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_user_memberships shortcode in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

6.4 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.