• Skip to primary navigation
  • Skip to main content

RocketGeek

Home of WP-Members, The Original WordPress Membership Plugin

  • WordPress Plugins
    • WP-Members
      • FAQs
      • Quick Start
      • Documentation
      • Extensions
    • Advanced Options
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • Download Protect
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • Invite Codes
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • MailChimp Integration
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • PayPal Subscriptions
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • Salesforce Web-to-Lead
    • Security
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • Text Editor
      • Purchase the Plugin
      • Get the Pro Bundle
    • User List
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • User Tracking
      • Documentation
      • Purchase the Plugin
      • Get the Pro Bundle
    • Memberships for WooCommerce
    • WordPass
  • Blog
    • Basics
    • Tips and Tricks
    • Filters
    • Actions
    • Code Snippets
    • Shortcodes
    • Design
    • Release Announcements
  • Store
    • Cart
    • Checkout
  • Contact
  • Log In
  • Show Search
Hide Search
Home » Release Announcements » WP-Members 2.8.10 released

WP-Members 2.8.10 released

Chad Butler · Jan 6, 2014 ·

This article is provided free. Find out how you can get full access to premium content, including how-to articles and support forums, as well as priority email support and member exclusive plugin extensions..

 

WP-Members 2.8.10 was released today.  This was an unexpected, but important security update.

Some of you may have noticed that for a period of time today, WP-Members was unavailable in the wordpress.org repository.  This was because there was a security vulnerability discovered in the plugin.  It is the policy of wordpress.org to remove any plugin that has a vulnerability until that issue is resolved.

I was notified of this issue at approximately 10:40 central time today.  By 12:30, I had created a patch which was tested and loaded to the repository by 2:00.  The plugin team at wordpress.org tested this new version and restored the plugin to the repository by 8:00.

I appreciate the prompt communication from the wordpress.org team.  We all take security seriously and their prompt contact with me allowed for a very quick turnaround in getting this fix out the door.

You might be wondering if you are affected by the vulnerability.  The issue actually only affects those users that use the WP-Members custom fields on the WordPress default backend registration (wp-login.php?action=register) instead of the plugin’s default frontside registration.  Since this is a feature that was only recently added specifically for users who did not read the plugin’s installation instructions, I suspect that this is only used by a small number of users (especially since the plugin’s default installation gives you a message to turn this off).

Regardless, I still recommend the update.

If you have any questions, please contact me.

Release Announcements

Ready to get started?

Join Today!

© 2025 · butlerblog.com · RocketGeek is built using WordPress, WP-Members, and the Genesis Framework

  • butlerblog.com
  • WP-Members Support Subscription
  • Terms of Service
  • Privacy Policy
  • Refund Policy