shouldiuse.io

Categories

VERDICT

Should I use ProfilePress?

WordPress membership, paywall, and user registration plugin - profilepress.com

Depends. Buy if you run a WordPress membership site, want memberships plus paywalls in one plugin, and will patch security releases fast. Skip if you're not on WordPress or can't tolerate its repeated CVE history.

Confidence

Medium. Based on 20+ public sources; many snippets truncated, so quote and stat granularity is limited.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo direct support evidence found
  • Security posture

Pricing

$0

Free

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Pro$129/yr

Best for

  • WordPress membership sites
  • Creators gating paid content
  • Subscription sellers on WordPress
  • Custom login/registration flows

Not for

  • Non-WordPress sites — it's a WP plugin, full stop
  • Teams that can't apply security patches within days
  • High-stakes paid communities where a breach is existential
  • Anyone wanting a set-and-forget paywall with zero admin work

Gotchas - check before you buy

high

Security patches are frequent; outdated versions have exposed sites to RCE and auth bypass

medium

Pro renews annually (~$129/yr); lifetime pricing was a limited-time AppSumo deal

medium

Switching later costs work — Paid Memberships Pro published a ProfilePress avatar migration guide

medium

Started as an avatar plugin, pivoted to memberships — users publicly questioned the roadmap

Pros and cons

Pros

  • Covers memberships, paywalls, registrations, and ecommerce in one plugin
  • Free core version available on
  • Lifetime-deal buyers call it great value for membership sites
  • Named among top WordPress membership plugins for 2026

Cons

  • Repeated vulnerabilities, including unauthenticated arbitrary plugin installation RCE
  • 2021 rebrand from avatar plugin triggered a user revolt
  • Some users call it one of the worst plugins they've used
  • Reviewers flag it as pricier than rivals

Sources & method

Analyzed 9/27/2026 - 10 sources - Nine-plus CVEs from 2021–2026, including critical RCE and auth bypass — patch discipline is mandatory.

official x1review x4security x3news x2
  • Unauthenticated arbitrary plugin installation leading to RCE (< 4.17.2), Unauthenticated attackers could install arbitrary plugins and achieve remote code execution on outdated versions.
  • CVE-2026-4949 authentication bypass, Auth bypass flaw in the membership/registration plugin disclosed April 2026.
  • CVE-2021-34621 critical, easily exploitable vulnerability, Critical flaw in ProfilePress described as easily exploitable, patched June 2021.
  • IDOR in <= 4.16.11, Authenticated subscribers could arbitrarily cancel or expire other subscriptions via insecure direct object reference.
  • CVE-2023-50882 missing authorization, Missing authorization vulnerability tracked by NIST.

Key stats

  • Value for money: 3/5

    Rating

  • $0

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 3/5. Lifetime deal praised; some reviewers say pricey
  • Ease of use: 3/5. Polarizing: fans and 'worst ever' reports
  • Feature depth: 4/5. Memberships, paywalls, ecommerce, registrations in one
  • Support quality. No direct support evidence found
  • Security posture: 1/5. Repeated CVEs including unauthenticated RCE
  • $129/yr Starting price Pro plan, per WPKube review
  • Yes Free version Free plugin on WordPress.org
  • ~400,000 Active installs Per Reddit discussion
  • 9+ CVEs since 2021 Incl. critical RCE and auth bypass

Pricing

Free

$0

  • User registration and login forms
  • User profiles
  • Basic content restriction

Pro

$129/yr

  • Paid memberships and ecommerce
  • Paywalls and content restriction
  • Payment gateway integrations

Security

Nine-plus CVEs from 2021–2026, including critical RCE and auth bypass — patch discipline is mandatory.

  • Unauthenticated arbitrary plugin installation leading to RCE (< 4.17.2)Unauthenticated attackers could install arbitrary plugins and achieve remote code execution on outdated versions.⁶
  • CVE-2026-4949 authentication bypassAuth bypass flaw in the membership/registration plugin disclosed April 2026.⁷
  • CVE-2021-34621 critical, easily exploitable vulnerabilityCritical flaw in ProfilePress described as easily exploitable, patched June 2021.⁸
  • IDOR in <= 4.16.11Authenticated subscribers could arbitrarily cancel or expire other subscriptions via insecure direct object reference.
  • CVE-2023-50882 missing authorizationMissing authorization vulnerability tracked by NIST.

What users say

Opinions are sharply split: some praise its feature depth and lifetime-deal value, while others find it frustrating or worse.

“ProfilePress is one of the worst plugins I've ever used”
Reddit, r/Wordpress
“Great lifetime deal for membership sites”
AppSumo review
“Decent, but not best”
WordPress.org support forums
Full analysis

Based on 20+ public sources; many snippets truncated, so quote and stat granularity is limited.

Capable all-in-one WordPress membership plugin, but a repeated CVE history means only buy it if you patch fast.

Methodology

Based on 20+ public sources; many snippets truncated, so quote and stat granularity is limited.

Sources

  1. review
  2. review
  3. review
  4. review
  5. news
  6. security
  7. security
  8. security
  9. official
  10. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.