shouldiuse.io

Categories

VERDICT

Should I use s2Member?

A powerful (free) membership plugin for WordPress - s2member.com

Depends. Buy it only if you run WordPress, sell memberships via PayPal/Stripe, and can handle heavy configuration plus fast security patching. Skip it if you want plug-and-play — a simpler plugin or hosted platform will fit better.

Confidence

Medium. Based on 20+ public sources: official docs, security databases, review sites, and forums. Many snippets truncated, so some figures are approximate.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Free framework

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Pro$99 (as listed by SourceForge)

Best for

  • WordPress membership/paywall sites
  • PayPal & Stripe subscription sellers
  • Technical owners comfortable with settings
  • BuddyPress/BuddyBoss communities

Not for

  • Non-technical users wanting plug-and-play
  • Security-sensitive sites handling member data
  • Non-WordPress sites
  • Anyone unwilling to patch within days of a CVE

Gotchas - check before you buy

high

CVE-2026-1994: unauthenticated privilege escalation via account takeover. Patch immediately if running it.

high

A Pro update broke live sites on PHP 8. Test on staging before upgrading.

medium

Free tier is limited; full features require a Pro license.

low

Legacy forums are read-only; expect KB articles and community channels over fast vendor support.

Pros and cons

Pros

  • Free core version with real functionality
  • Supports both PayPal and Stripe payments
  • Unlimited memberships and content restriction levels
  • Integrates with BuddyPress/BuddyBoss communities
  • One-time license cost versus monthly SaaS fees

Cons

  • Repeated CVEs, including unauthenticated privilege escalation
  • Overwhelming number of configuration options
  • Pro update broke sites running PHP 8
  • Key features locked behind paid Pro license
  • Local file inclusion and XSS vulnerabilities on record

Sources & method

Analyzed 9/27/2026 - 12 sources - Active, maintained plugin, but a 2024–2026 trail of CVEs including critical unauthenticated privilege escalation — patching discipline is mandatory.

official x2review x5security x4news x1
  • CVE-2026-1994 — Unauthenticated Privilege Escalation via Account Takeover, Critical flaw allowing attackers to take over accounts and escalate privileges in s2Member.
  • Local File Inclusion vulnerability, LFI flaw in the s2Member plugin tracked by Patchstack (2025).
  • CVE-2024-12562, s2Member vulnerability tracked in NIST NVD, February 2025.
  • CVE-2026-15047 — XSS, Cross-site scripting vulnerability in the s2Member plugin.

Key stats

  • Value for money: 4/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 4/5. Free core, one-time license beats monthly SaaS
  • Ease of use: 2/5. Reddit calls options 'mind boggling'
  • Feature depth: 4/5. Stripe, PayPal Pro, unlimited memberships, BuddyPress
  • Support quality: 2/5. Forum-based; refund requests, read-only legacy forums
  • Security posture: 1/5. Multiple CVEs, unauthenticated privilege escalation
  • $99 Starting price Pro license, per SourceForge listing
  • Yes Free tier Free framework version
  • 5,000+ Sites using it Tracked by BuiltWith

Pricing

Free framework

$0

  • Content restriction and paywalls
  • Basic PayPal checkout

Pro

$99 (as listed by SourceForge)

  • Stripe and PayPal Pro support
  • Unlimited-Site License option available

Security

Active, maintained plugin, but a 2024–2026 trail of CVEs including critical unauthenticated privilege escalation — patching discipline is mandatory.

  • CVE-2026-1994 — Unauthenticated Privilege Escalation via Account TakeoverCritical flaw allowing attackers to take over accounts and escalate privileges in s2Member.³
  • Local File Inclusion vulnerabilityLFI flaw in the s2Member plugin tracked by Patchstack (2025).⁴
  • CVE-2024-12562s2Member vulnerability tracked in NIST NVD, February 2025.⁵
  • CVE-2026-15047 — XSSCross-site scripting vulnerability in the s2Member plugin.⁶

What users say

Users value its depth and low cost but frequently complain about configuration complexity and security upkeep.

“S2member is great for be…”
Reddit, r/Entrepreneur
“Mind Boggling Number of Options for WordPress…”
Reddit, r/Wordpress
Full analysis

Based on 20+ public sources: official docs, security databases, review sites, and forums. Many snippets truncated, so some figures are approximate.

Powerful free WordPress paywall, but config-heavy with a shaky security record. Fits technical WP owners; others should look elsewhere.

Methodology

Based on 20+ public sources: official docs, security databases, review sites, and forums. Many snippets truncated, so some figures are approximate.

Sources

  1. official
  2. official
  3. security
  4. security
  5. security
  6. security
  7. review
  8. review
  9. review
  10. review
  11. review
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.