shouldiuse.io

VERDICT

Should I use ARMember?

⚡ Limited Offer - armemberplugin.com

Depends. Buy it if you run WordPress, sell memberships or courses, and will apply security patches immediately. Skip it if you need a simple paywall or can't tolerate a plugin with a long CVE history.

Confidence

Medium. Based on 20+ public sources, including 7 security advisories

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Lite

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Standard$99/year ($89 promo)

Best for

  • WordPress sites selling subscriptions
  • Online courses and paid content
  • Community sites with gated access
  • Solo creators monetizing content

Not for

  • Non-WordPress sites — it's a WP plugin only
  • Simple paywall needs — overkill, use something lighter
  • Teams that won't patch within days of advisories
  • Buyers allergic to annual license renewals

Gotchas - check before you buy

high

Multiple CVEs 2022–2026; one advisory said 'temporarily disable ARMember'. Update immediately on release.

medium

Yearly licensing: renew to keep updates and support; 'limited offer' discounts run constantly.

medium

Payments and member data live on your WordPress host; you own hardening, backups, and PCI scope.

low

Lite version is limited; real features require the paid license.

Pros and cons

Pros

  • Full suite: subscriptions, payments, content access rules
  • Supports 21+ payment gateways
  • Support frequently praised by buyers
  • Often recommended in Reddit WordPress communities
  • Free Lite version to test first

Cons

  • Repeated CVEs: SQL injection, XSS, privilege escalation
  • Advisories urged temporarily disabling the plugin
  • Annual license renewal required
  • Some users report issues and shop for alternatives

Sources & method

Analyzed 9/27/2026 - 14 sources - Significant CVE history (2022–2026): SQL injection, stored XSS, privilege escalation, plan bypass. Patch discipline is essential.

official x2review x7security x5
  • CVE-2026-7649 — SQL injection, SQL injection vulnerability in the ARMember plugin, reported May 2026.
  • CVE-2026-5073 — SQL injection advisory, Advisory published June 2026 urged temporarily disabling ARMember.
  • CVE-2022-42888 — Unauthenticated privilege escalation, Unauthenticated privilege escalation vulnerability in ARMember.
  • CVE-2022-47421 — Authenticated stored XSS, Authenticated stored cross-site scripting vulnerability.
  • Membership plan bypass (v4.0.10), Membership plan bypass vulnerability, disclosed November 2023.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 4/5. $99/yr covers the full suite
  • Ease of use: 3/5. Capable but user threads show setup friction
  • Feature depth: 5/5. Subscriptions, 21+ gateways, access rules, add-ons
  • Support quality: 4/5. Support praised across multiple review sites
  • Security posture: 2/5. Repeated CVEs: SQLi, XSS, escalation
  • $99/yr Starting price Standard plan, $89 promo
  • 11,000+ Customers Vendor claim
  • 21+ Payment gateways Per Trustpilot listing
  • Yes Free tier ARMember Lite plugin

Pricing

Lite

Free

  • Limited core membership features
  • Available as a separate Lite plugin

Standard

$99/year ($89 promo)

  • Subscriptions and recurring payments
  • 21+ payment gateways
  • Content access rules and add-ons

Security

Significant CVE history (2022–2026): SQL injection, stored XSS, privilege escalation, plan bypass.

  • CVE-2026-7649 — SQL injectionSQL injection vulnerability in the ARMember plugin, reported May 2026.10
  • CVE-2026-5073 — SQL injection advisoryAdvisory published June 2026 urged temporarily disabling ARMember.11

Patch discipline is essential.

  • CVE-2022-42888 — Unauthenticated privilege escalationUnauthenticated privilege escalation vulnerability in ARMember.12
  • CVE-2022-47421 — Authenticated stored XSSAuthenticated stored cross-site scripting vulnerability.
  • Membership plan bypass (v4.0.10)Membership plan bypass vulnerability, disclosed November 2023.13

What users say

Buyers praise feature breadth and responsive support, while Reddit threads also surface users troubleshooting issues or shopping for alternatives.

“Completely worth the purchase! High-quality WP Member Plugin Great Support”
WordPress.org support forum
“You should try ARMember”
Reddit, r/Wordpress
“Great support”
Trustindex review
Full analysis

Based on 20+ public sources, including 7 security advisories

Feature-rich WP membership plugin ($99/yr), but repeated CVEs — SQLi, privilege escalation — mean you must patch fast.

Methodology

Based on 20+ public sources, including 7 security advisories

Sources

  1. ARMember homepagearmemberplugin.com
    official
  2. ARMember pricingarmemberplugin.com
    official
  3. review
  4. review
  5. review
  6. review
  7. review
  8. review
  9. review
  10. security
  11. security
  12. security
  13. security
  14. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.