Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
by properfraction · eCommerce
Also makes 4 other plugins · 230K+ installs across the portfolio →
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
76 health vs 68 average across 5,563 eCommerce plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Rating quality
To rank higher: Lift the average: resolve the issues driving the low reviews.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,422 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
107.4K
now · peak 346.9K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
14
releases in the last 12 months
2mo ago
latest release · v4.16.19
215
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-21 · 1,485 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ 1question2mo ago
Hi, Big thanks for this plugin : )
Read on wp.org ↗ - ★★★★★ jacobdreizin3mo ago
My paywalled/subscription website crashed when ProfilePress pushed an update with a small error in the coding (in the part responsible for user avatar pics, of all things), but the support was very responsive, and resolved the problem on the same day, in fact within at most 5 hours of my first communication, which I was really not expecting. Thank you!
Read on wp.org ↗ - ★★★★★ mvxweb3mo ago
The content restriction feature is straightforward and works reliably. Tested with different user accounts and membership levels, and access was always enforced correctly. No fuss. No confusing setup.
Read on wp.org ↗ - ★★★★★ Ryan4mo ago
This is an excellent plug‑in. I’m surprised I haven’t heard about it before. Shockingly, it integrates with multiple prominent LMS platforms, including LearnDash, and the platform is very user‑friendly. So I feel I’ve got great value for money. I hope the developers or the owners keep updating and improving the plugin.
Read on wp.org ↗ - ★★★★★ negru135mo ago
This used to be WP User Avatar. Now is this bloated usless plugin. Not what I asked for.
Read on wp.org ↗ - ★★★★★ weswebmaster6mo ago
We are working towards a new website, and the ProfilePress team have been extremely supportive in answering queries and even responding to feature requests. Great team! Thank you.
Read on wp.org ↗ - ★★★★★ chaney2207mo ago
I was using Profile Press for a little bit but found that it just didn’t have all of the options that I needed for my customers’ profiles. I started using Ultimate Member, and it has many more features.
Read on wp.org ↗ - ★★★★★ devmickey7mo ago
I’ve been using ProfilePress for memberships and payments, and it has become a core part of my WordPress setup. It’s a powerful ecommerce and paid membership plugin that supports one-time and recurring payments, selling subscriptions, and restricting content behind a paywall with access to control rules. Their plugin is well documented, so everyone should be able to set it up. On top of that, it’s very flexible on the front end: you can build custom registration, login, password reset, and edit-profile forms using a drag-and-drop builder, and you can also create user profiles and member directories. What truly stands out is their team: fast responses, clear answers, and genuine willingness to think along and propose practical solutions. Special mention to Ibrahim and Collins who consistently go above and beyond with tailored fixes and implementations. They really do listen to their community and have a can-do mentality when it comes to changing the product to meet customer expectations. Overall, highly recommended for anyone building a membership site or selling digital products on WordPress. Good luck on the further development!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 4.16.19 Add optional order creation to the Add New Customer screen. Fixed bug where suppressed email still went out. Fixed security issue where other file types (exe, msi) could be uploaded outside ProfilePress upload scope. Imp 4.16.19
- — Version 4.16.18 Added compatibility with Yoast URL Cleanup feature. Fix security issue where non-admin user role can be passed as user role. 4.16.18
- — Version 4.16.17 Fixed security issue a user subscription can be canceled by another user. 4.16.17
- — Version 4.16.16 Pro: Paddle addon . Added password visibility icons to the password reset handler form fields 4.16.16
- — Version 4.16.15 Pro: Brevo addon . Pro: Auto-Renewal Checkbox addon . Added filters to the test mode notice and checkout username. Added membership conditions to Elementor display rules. See the changelog file for full change log inform 4.16.15
- — Version 4.17.0 Premium: Added Pay What You Want addon . Added Subscription Payment Failed email notification. Fixed Stripe bug where email change caused checkout failure. Fixed fatal error when price has a currency symbol or thousands 4.17.0
Known vulnerabilities
via Wordfence Intelligence47 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-15 CVE-2026-18385 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.19 Patched in 4.17.0
- 2026-07-16 CVE-2026-13352 Unrestricted Upload of File with Dangerous Type Affects <= 4.16.18 Patched in 4.16.19
- Medium · 4.3 ProfilePress <= 4.16.16 - Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation ↗2026-06-06 CVE-2026-10820 Authorization Bypass Through User-Controlled Key Affects <= 4.16.16 Patched in 4.16.17
- 2026-04-23 CVE-2026-41556 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.13 Patched in 4.16.14
- 2026-04-03 CVE-2026-3309 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.11 Patched in 4.16.12
- 2026-03-10 CVE-2026-3453 Authorization Bypass Through User-Controlled Key Affects <= 4.16.11 Patched in 4.16.12
- 2025-12-08 CVE-2025-13642 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.7 Patched in 4.16.8
- 2025-08-15 CVE-2025-8878 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.4 Patched in 4.16.5
- 2025-01-23 CVE-2024-13120 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.19 Patched in 4.15.20
- 2025-01-23 CVE-2024-13121 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.19 Patched in 4.15.20
- 2025-01-23 CVE-2024-13119 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.19 Patched in 4.15.20
- Medium · 5.3 ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure ↗2024-11-26 CVE-2024-11083 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.15.18 Patched in 4.15.19
- Medium · 4.4 ProfilePress <= 4.15.14 - Authenticated (Admin+) Stored Cross-Site Scripting via "Labels" ↗2024-11-21 CVE-2024-10517 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.14 Patched in 4.15.15
- Medium · 4.4 ProfilePress <= 4.15.14 - Authenticated (Admin+) Stored Cross-Site Scripting via "Product Files" ↗2024-11-21 CVE-2024-10518 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.14 Patched in 4.15.15
- 2024-05-22 CVE-2024-2861 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.8 Patched in 4.15.9
- 2024-04-09 CVE-2024-3210 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.5 Patched in 4.15.6
- Medium · 6.4 ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2024-03-12 CVE-2024-1535 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.2 Patched in 4.15.3
- 2024-02-23 CVE-2024-1806 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.1 Patched in 4.15.2
- 2024-02-22 CVE-2024-1409 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.0 Patched in 4.15.1
- Medium · 6.4 ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2024-02-19 CVE-2024-1570 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.4 Patched in 4.15.0
- 2024-02-19 CVE-2024-1519 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.4 Patched in 4.15.0
- 2024-02-19 CVE-2024-1408 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.4 Patched in 4.15.0
- 2024-02-01 CVE-2024-1046 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.3 Patched in 4.14.4
- 2023-10-02 CVE-2023-44150 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.13.2 Patched in 4.13.3
- 2023-06-23 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.11.0 Patched in 4.11.0
- 2023-03-27 CVE-2022-47444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.3 Patched in 4.5.4
- 2023-02-21 CVE-2023-23830 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.4 Patched in 4.5.5
- Medium · 6.4 ProfilePress <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes ↗2023-02-20 CVE-2023-23820 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.4 Patched in 4.5.5
- 2023-01-20 CVE-2023-23996 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.3 Patched in 4.5.4
- 2022-12-23 CVE-2022-4697 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.0 Patched in 4.5.1
- Medium · 5.5 ProfilePress <= 4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings ↗2022-12-23 CVE-2022-4698 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.0 Patched in 4.5.1
- 2022-07-22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.15 Patched in 3.2.16
- 2021-11-15 CVE-2021-24955 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.3 Patched in 3.2.3
- 2021-11-15 CVE-2021-24954 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.3 Patched in 3.2.3
- 2021-08-09 CVE-2021-24522 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.10 Patched in 3.1.11
- Critical · 9.8 ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload ↗2021-06-28 CVE-2021-34624 Unrestricted Upload of File with Dangerous Type Affects 3.0.0 - 3.1.3 Patched in 3.1.4
- 2021-06-28 CVE-2021-24450 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.1.8 Patched in 3.1.8
- 2021-06-28 CVE-2021-34623 Unrestricted Upload of File with Dangerous Type Affects 3.0.0 - 3.1.3 Patched in 3.1.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 35 languages, 5 at 90% or more
Plus 11 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-06-14 200K+ → 100K+ down after 651 days in tier
- 2023-09-02 300K+ → 200K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 200K+ installs · 4.4★ · 3 shared tags A -
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 50K+ installs · 4.8★ · 3 shared tags A -
User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission 20K+ installs · 4.1★ · 3 shared tags A -
WP User Manager – User Profile Builder & Membership 10K+ installs · 4.7★ · 3 shared tags A -
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 40K+ installs · 4.7★ · 2 shared tags A -
Simple Membership 40K+ installs · 4.6★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wp-user-avatar" width="480" height="300" style="border:0" loading="lazy" title="Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — Plugin Pulse"></iframe> Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: 100K+ active installs, 3.1★ (937 reviews). Plugin Pulse (WP Mayor), as of 2026-08-26. https://plugins.wpmayor.com/plugin/wp-user-avatar