User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
by wpeverest · Membership
Also makes 5 other plugins · 140.8K+ installs across the portfolio →
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
98 health vs 69 average across 180 Membership plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
48.1K
now · peak 151.4K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
28
releases in the last 12 months
2mo ago
latest release · v5.2.5
189
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 47% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “50K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2018-03-16 · 1,447 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 5.2.6 Enhance – Compatibility with divi 5. Enhance – Allow 100% discount coupons on memberships. Enhance – Redirect hint links to Enable Custom Redirect setting. Fix – Local currency bugs. Fix – Double Charge on Upgrade. Fix – 5.2.6
- — Version 5.2.5 Enhance – Defer expiry to period end. Enhance – Pin Stripe subscription payment method for reliable renewals. Fix – User and admin email order. Fix – Payment fail case for paypal. Fix – Lost Password Carrot adjustment. F 5.2.5
- — Version 5.2.4 Enhance – User role overwritten on new membership assignment. Enhance – Add customizable membership registration success message in settings. Fix – Duplicate variable. Fix – Invoice dynamic content not translatable. Fix 5.2.4
- — Version 5.2.3 Fix – validation for receiver email and payment amount in PayPal IPN handling. Fix – Selected membership tier during registration missed proper validation, allowing assignment of off-form membership tiers. Fix – Stripe s 5.2.3
- — Version 5.2.2 Dev – Add UR_WPML compatibility service class. Fix – Password reset link shows “invalid or expired” error. Fix – Membership subscriptions stuck pending on 3D Secure (SCA) cards. Fix – Hardcoded database table names causi 5.2.2
- — Version 5.2.1 Fix – Stripe order validation issue. Fix – Membership upgrade action not available after disabling group add-on. Fix – Custom emails addon cannot be enabled with plus plan even available in personal. Fix – Nav menu items 5.2.1
Known vulnerabilities
via Wordfence Intelligence48 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 5.3 User Registration & Membership <= 5.2.2 - Missing Authorization to Unauthenticated User Deletion via Stripe Handler ↗2026-06-26 CVE-2026-11966 Authorization Bypass Through User-Controlled Key Affects <= 5.2.2 Patched in 5.2.3
- 2026-06-22 CVE-2026-11963 Authorization Bypass Through User-Controlled Key Affects <= 5.2.1 Patched in 5.2.2
- 2026-06-11 CVE-2026-11965 Client-Side Enforcement of Server-Side Security Affects <= 5.1.0 Patched in 5.2.0
- 2026-05-27 CVE-2026-7651 Authorization Bypass Through User-Controlled Key Affects <= 5.1.5 Patched in 5.1.6
- Medium · 6.1 User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter ↗2026-04-13 CVE-2026-6203 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 5.1.4 Patched in 5.1.5
- 2026-04-09 CVE-2026-42652 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.1.5 Patched in 5.1.6
- Medium · 6.5 User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[] ↗2026-04-07 CVE-2026-1865 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.2 Patched in 5.1.3
- 2026-02-25 CVE-2026-1779 Authentication Bypass Using an Alternate Path or Channel Affects <= 5.1.2 Patched in 5.1.3
- Medium · 5.3 User Registration <= 4.4.6 - Missing Authorization ↗
- Medium · 5.4 User Registration <= 4.4.9 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ↗2026-01-08 CVE-2026-24353 Improper Control of Generation of Code ('Code Injection') Affects <= 4.4.9 Patched in 5.0
- 2025-12-15 CVE-2025-13367 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.6 Patched in 4.4.7
- 2025-09-05 CVE-2025-9085 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.3.0 Patched in 4.4.0
- Medium · 6.4 User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode ↗2025-07-21 CVE-2025-6831 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.4 Patched in 4.3.0
- 2025-05-05 CVE-2025-3281 Authorization Bypass Through User-Controlled Key Affects <= 4.2.1 Patched in 4.2.2
- 2025-04-22 CVE-2025-39400 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.1.5 Patched in 4.2.0
- 2025-04-11 CVE-2025-3292 Authorization Bypass Through User-Controlled Key Affects <= 4.1.3 Patched in 4.1.4
- 2025-04-11 CVE-2025-3282 Authorization Bypass Through User-Controlled Key Affects <= 4.1.3 Patched in 4.1.4
- 2025-04-01 CVE-2025-2594 Authentication Bypass Using an Alternate Path or Channel Affects <= 4.1.2 Patched in 4.1.3
- Medium · 4.4 User Registration <= 4.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2025-03-27 CVE-2025-30899 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.0.3 Patched in 4.0.4
- 2025-02-27 CVE-2025-1511 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.0.4 Patched in 4.1.0
- 2024-03-06 CVE-2024-1720 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.4 Patched in 3.1.5
- 2023-10-16 CVE-2023-5228 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.4.1 Patched in 3.0.4.2
- 2023-07-04 CVE-2023-3342 Unrestricted Upload of File with Dangerous Type Affects <= 3.0.2 Patched in 3.0.2.1
- Medium · 5.5 User Registration <= 2.3.0 - Authenticated (Administrator+) Stored Cross Site Scripting ↗2023-01-20 CVE-2023-23987 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.3.0 Patched in 2.3.1
- 2022-11-21 CVE-2022-3912 Unrestricted Upload of File with Dangerous Type Affects <= 2.2.4 Patched in 2.2.41
- Medium · 6.4 User Registration <= 1.5.5 - Cross-Site Scripting ↗2019-01-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.5 Patched in 1.5.6
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 17 languages, 1 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-06-28 60K+ → 50K+ down after 353 days in tier
- 2025-07-10 70K+ → 60K+ down after 4 days in tier
- 2025-07-06 60K+ → 70K+ up after 2 days in tier
- 2025-07-04 70K+ → 60K+ down after 2 days in tier
- 2025-07-02 60K+ → 70K+ up after 2 days in tier
- 2025-06-30 70K+ → 60K+ down after 63 days in tier
- 2025-04-28 60K+ → 70K+ up after 301 days in tier
- 2024-07-01 70K+ → 60K+ down after 76 days in tier
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 200K+ installs · 4.4★ · 3 shared tags A -
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 100K+ installs · 3.1★ · 3 shared tags B -
User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission 20K+ installs · 4.1★ · 3 shared tags A -
WP User Manager – User Profile Builder & Membership 10K+ installs · 4.7★ · 3 shared tags A -
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction 10K+ installs · 4.7★ · 3 shared tags A -
Membership For WooCommerce 900+ installs · 4.3★ · 3 shared tags A
Embed this report card
Drop a live Pulse card for User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/user-registration" width="480" height="300" style="border:0" loading="lazy" title="User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder — Plugin Pulse"></iframe> User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 50K+ active installs, 4.8★ (828 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/user-registration