Confidence
Medium. Based on 20+ public sources, including 7 security advisories
Pricing
Free
Lite
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Standard$99/year ($89 promo)
Sources & method
Analyzed 9/27/2026 - 14 sources - Significant CVE history (2022–2026): SQL injection, stored XSS, privilege escalation, plan bypass. Patch discipline is essential.
official x2review x7security x5
- CVE-2026-7649 — SQL injection, SQL injection vulnerability in the ARMember plugin, reported May 2026.
- CVE-2026-5073 — SQL injection advisory, Advisory published June 2026 urged temporarily disabling ARMember.
- CVE-2022-42888 — Unauthenticated privilege escalation, Unauthenticated privilege escalation vulnerability in ARMember.
- CVE-2022-47421 — Authenticated stored XSS, Authenticated stored cross-site scripting vulnerability.
- Membership plan bypass (v4.0.10), Membership plan bypass vulnerability, disclosed November 2023.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.