User Registration & Membership Pro icon

Release v6.2.8

User Registration & Membership Pro v6.2.8

Latest version

What's new in v6.2.8

User Registration & Membership Pro v6.2.8 was released on . Skip to content Trusted by 60,000+ Users User Registration & Membership for WordPress Create custom registration forms, manage users, and sell memberships from a single plugin. See the full changelog below and compare with the complete version history.

Release details

Released
17.0 MB
File available

Changelog

Fixed
  • Standardized Pro upgrade link UTMs.
  • Stored XSS in the Form Analytics user journey table.
  • Hardened form analytics queries with prepared statements.
  • Content restriction bypassed via WordPress core REST API.
  • Team Membership: invited members now receive the plan's role.
  • Team Membership: team leaders could edit teams they don't lead.
  • Standardized outbound UTM parameters and invalid campaign keys.
  • Users could be redirected to an outside website after logging in.
  • Frontend Listing title-save request could rename unrelated posts.
  • Unauthenticated force-logout of any user via ?force-logout= .
  • Membership thank you page exposed another member's account details.
  • Team Membership: scoped Edit Team form nonce to the team being edited.
  • Use timing-safe comparison for email confirmation and approval tokens.
  • Stripe payment could be replayed to renew a membership without paying.
  • Privilege escalation via membership role and open redirect after login.
  • Coupons and Frontend Listing bulk delete triggerable via a crafted link.
  • Coupons AJAX handlers allowed arbitrary post deletion and coupon minting.
  • Tax regions and rates could be deleted without a nonce or permission check.
  • Expired membership could be renewed by replaying an earlier Stripe payment.
  • Deactivate License button did nothing when pro-activation transient was set.
  • Team Membership: plan role now removed when a member leaves or the team ends.
  • Registration forms not validating publish status or restricting assigned roles.
  • SMS OTP could be brute-forced to take over an account; now rate-limited and session-bound.
Added
  • `{{force_logout_url}}` smart tag for Pro's prevent concurrent login email.

Compatibility

Requires WordPress
5.5
Tested up to
7.1
Requires PHP
7.4

Verified safe

User Registration & Membership Pro v6.2.8 scanned clean with no security threats detected.

View full scan report