The plugin avoids checking role names for access to various administrative functions as this is not the proper way to control access. WP is a capability-based ruleset, and users can have multiple roles, and various roles can have different capabilities.
For example, the default WP admin role has edit_users permissions, and a custom role created to manage users but not only things the WP admin role can manage can also be given edit_users capability.
The following lists the primary restricted elements of the plugin and what capabilities they are restricted to. Some of the capabilities can be customized (to change the capability checked) by using a filter. If the capability requirement is filterable, it is listed.
All of the default capabilities listed below are only found in the administrator role if your WP instance is simply a default instance (i.e. no custom roles). However, you should not use a role definition if restricting with current_user_can(); rather, this should check the necessary user capability.
A role editor such as User Role Editor will allow you to manage the capabilities assigned to existing roles, and/or create custom roles with unique capability sets based on your specific needs.
Managing plugin options
The plugin’s admin screen is only accessible if the user has manage_options capability.
Managing memberships
This includes adding/editing/deleting membership properties as well as creating new memberships.
To add/edit/delete memberships: manage_options
To filter the capability for displaying the [wpmem_field] shortcode: wpmem_field_sc_required_capability
Default: list_users
Export users
Default capability: list_users
Filter: wpmem_export_args
Array value in filter: $defaults['required_caps']
Admin fields in dashboard user profile
This includes viewing “admin only” fields as well as activating/deactivating users and viewing the WP-Members profile tabs.
Default capability: edit_users
Filter: wpmem_user_profile_caps
Filter is a string value only for this.
See posts in admin that are marked as hidden
Default capability: edit_posts
Filter: none
Admin user actions
The plugin only loads its customizations for the Users > All Users screen for users that have list_users capability. There is no filter to change this, since a user without that capability wouldn’t be able to view that screen anyway. This includes custom user filter views, bulk actions (activate/deactivate, confirm/unconfirm), and user row hover links.
User search and user export is only added if user has list_users capability.
Custom plugin actions attached to post/page editor and all posts/pages screen
The plugin only loads these actions if the user has edit_posts capability. If they didn’t have this capability, they wouldn’t be able to view any of the associated screens anyway.