
WPCOM Member Security & Risk Analysis
wordpress.org/plugins/wpcom-memberWPCOM Member - User profile & membership plugin for WordPress
Is WPCOM Member Safe to Use in 2026?
Mostly Safe
Score 80/100WPCOM Member is generally safe to use. 7 past CVEs were resolved. Keep it updated.
The 'wpcom-member' plugin version 1.7.19 exhibits a concerning security posture, despite some positive aspects. While it demonstrates good practices in utilizing prepared statements for SQL queries and proper output escaping, significant vulnerabilities are present in its attack surface and past security history. A substantial number of AJAX handlers (32 out of 39) lack authentication checks, creating a wide entry point for attackers. Furthermore, the taint analysis revealed four high-severity flows with unsanitized paths, indicating potential for critical exploits if these flows are triggered by user input. The plugin's vulnerability history is also a major red flag, with a significant number of known CVEs, including two critical and four high-severity ones, even though none are currently unpatched. The recurring vulnerability types such as Remote File Inclusion, SQL Injection, and Cross-site Scripting suggest fundamental security weaknesses that have been historically difficult to fully address. While the absence of bundled libraries and the use of nonces and capability checks on some entry points are positive, the numerous unprotected AJAX handlers and the history of severe vulnerabilities paint a picture of a plugin that requires immediate attention and remediation to mitigate significant risks.
Key Concerns
- High number of AJAX handlers without auth checks
- 4 High severity taint flows with unsanitized paths
- 2 Critical CVEs historically
- 4 High severity CVEs historically
- Recurring vulnerability types (RFI, SQLi, XSS, Auth)
WPCOM Member Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
WPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTP
WPCOM Member <= 1.7.14 - Authenticated (Contributor+) Local File Inclusion via Shortcode
WPCOM Member <= 1.7.7 - Authenticated (Contributor+) Local File Inclusion
WPCOM Member <= 1.7.6 - Unauthenticated Time-Based SQL Injection
WPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone'
WPCOM Member <= 1.5.4 - Reflected Cross-Site Scripting
WPCOM Member <= 1.5.2.1 - Unauthenticated Privilege Escalation via User Meta
WPCOM Member Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPCOM Member Attack Surface
AJAX Handlers 39
Shortcodes 2
WordPress Hooks 143
Scheduled Events 3
Maintenance & Trust
WPCOM Member Maintenance & Trust
Maintenance Signals
Community Trust
WPCOM Member Alternatives
Members – Membership & User Role Editor Plugin
members
The best WordPress membership and user role editor plugin. User Roles & Capabilities editor helps you restrict content in just a few clicks.
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
WP-Members Membership Plugin
wp-members
The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.
WPCOM Member Developer Profile
2 plugins · 1K total installs
How We Detect WPCOM Member
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcom-member/assets/css/style.css/wp-content/plugins/wpcom-member/assets/js/member.js/wp-content/plugins/wpcom-member/assets/css/cropper.min.css/wp-content/plugins/wpcom-member/assets/js/cropper.min.js/wp-content/plugins/wpcom-member/assets/js/member-shortcode.js/wp-content/plugins/wpcom-member/assets/js/member.js/wp-content/plugins/wpcom-member/assets/js/cropper.min.js/wp-content/plugins/wpcom-member/assets/js/member-shortcode.jswpcom-member/assets/css/style.css?ver=wpcom-member/assets/js/member.js?ver=HTML / DOM Fingerprints
wpcom-member-register-formwpcom-member-login-formwpcom-member-profilewpcom-member-shortcode<!-- wpcom-member: Shortcode START --><!-- wpcom-member: Shortcode END -->data-wpcom-member-noncewpcom_member_params/wp-json/wpcom-member/v1/user-posts/wp-json/wpcom-member/v1/user-comments/wp-json/wpcom-member/v1/login-modal[wpcom-member]