shouldiuse.io

VERDICT

Should I use Paid Memberships Pro?

Restrict content, manage member subscriptions with recurring payments for Stripe and PayPal. Custom profiles and robust member management. - paidmembershipspro.com

Depends. Buy if you run WordPress and need gated content with Stripe/PayPal subscriptions, and you will keep the plugin patched. Skip it if you are off WordPress or want a hands-off hosted membership platform.

Confidence

Medium. Based on 20+ public sources: reviews, Reddit threads, CVE databases, and official pages.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo user support evidence in sources
  • Security posture

Pricing

$0

Core plugin

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Paid plansSee pricing page

Best for

  • WordPress sites selling memberships
  • Creators gating content behind subscriptions
  • Sites migrating off Patreon

Not for

  • Non-WordPress projects
  • Teams wanting zero plugin maintenance
  • Simple one-off paywalls — lighter tools suffice

Gotchas - check before you buy

high

Repeated CVEs (SQLi, CSRF, auth bypass) mean slow patching is genuinely risky

medium

Percentage-fee friction: a July 2025 Reddit PSA says avoiding it became harder

medium

Left in Oct 2024 — installs and updates now flow through the vendor

low

G2 score is 4.8 from just 4 reviews — statistically thin

Pros and cons

Pros

  • Free core plugin with content restriction and member management
  • Stripe and PayPal recurring payments built in
  • Large add-on ecosystem, including WooCommerce integration
  • Rated easy to use in 2026 WPKube review
  • Big installed base: 90,000+ sites claimed

Cons

  • History of SQL injection, CSRF, and auth-bypass CVEs
  • Left the repo in October 2024
  • Reddit PSA: avoiding a percentage fee got harder in 2025
  • G2's 4.8 rests on only 4 reviews
  • Membership Geeks scored it a middling 3.9/5

Sources & method

Analyzed 9/21/2026 - 10 sources - Multiple CVEs (SQLi, CSRF, auth bypass) across 2023–2026; patching discipline is mandatory.

official x2review x4security x2news x2
  • CVE-2023-23488 — SQL injection, Unauthenticated SQL injection vulnerability in the plugin.
  • CVE-2024-37277 — authorization bypass, Authorization bypass flaw listed in NVD.
  • CVE-2024-1407 — CSRF, Cross-site request forgery vulnerability.
  • SQL injection in v3.0.5, Content restriction, registration, and subscriptions SQL injection listing.

Key stats

  • Value for money: 3/5

    Rating

  • $0

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 3/5. Free core, but fee-friction complaints
  • Ease of use: 4/5. WPKube review calls it easy
  • Feature depth: 4/5. Deep add-on set, WooCommerce integration
  • Support quality. No user support evidence in sources
  • Security posture: 2/5. Repeated SQLi, CSRF, auth-bypass CVEs
  • 4.8/5 G2 rating only 4 reviews
  • 4.5/5 WPKube rating 2026 review
  • Yes Free tier core plugin is 100% free
  • 90,000+ Sites using it company-claimed

Pricing

Core plugin

$0

  • Content restriction
  • Stripe & PayPal recurring payments
  • Member management

Paid plans

See pricing page

  • Add-ons
  • Support

Security

Multiple CVEs (SQLi, CSRF, auth bypass) across 2023–2026; patching discipline is mandatory.

  • CVE-2023-23488 — SQL injectionUnauthenticated SQL injection vulnerability in the plugin.⁷
  • CVE-2024-37277 — authorization bypassAuthorization bypass flaw listed in NVD.⁸
  • CVE-2024-1407 — CSRFCross-site request forgery vulnerability.
  • SQL injection in v3.0.5Content restriction, registration, and subscriptions SQL injection listing.

What users say

WordPress reviewers rate it well (3.9–4.8), but Reddit threads flag fee changes and its exit from the wordpress.org repo.

“PSA: Paid Memberships Pro is making it more difficult to avoid the 2 ...”
Reddit, r/Wordpress
“Paid Memberships Pro is leaving the wordpress.org repo”
Reddit, r/Wordpress

Companies that use it

  • Playful Learning
  • Buyer Defend
Full analysis

Based on 20+ public sources: reviews, Reddit threads, CVE databases, and official pages.

Solid WordPress membership plugin, free core, 90k+ sites — but CVE history and the 2024 repo exit mean real upkeep.

Methodology

Based on 20+ public sources: reviews, Reddit threads, CVE databases, and official pages.

Sources

  1. review
  2. review
  3. review
  4. review
  5. news
  6. news
  7. security
  8. security
  9. Pricing and Plans — PMPropaidmembershipspro.com
    official
  10. Free core plugin — PMPropaidmembershipspro.com
    official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.