Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A WordPress bug bounty program is a controlled way for security researchers to report vulnerabilities privately so the WordPress security team can verify, fix and responsibly disclose them. WordPress identifies HackerOne as the required reporting channel for Core security issues. A valid report may receive recognition or a discretionary payment, but no bounty is guaranteed.

What the official WordPress program covers

WordPress’s security policy says its HackerOne program covers “the Core software, as well as a variety of related projects and infrastructure.” WordPress Core is therefore the central scope, while the live policy determines which related projects, systems and exclusions are currently eligible.

The WordPress.org security guidance directs anyone who believes they found a WordPress Core vulnerability to the official HackerOne channel at hackerone.com/wordpress. Automattic’s policy separately directs reports for the WordPress, BuddyPress and bbPress open-source projects to that WordPress HackerOne program.

Where to report a WordPress security vulnerability

  1. Check scope first. Confirm that the asset, version, project and testing activity are allowed by the current WordPress HackerOne policy.
  2. Use an authorized test setup. Follow applicable law, use accounts you own or are authorized to test, and do not access or alter other users’ data.
  3. Document a reproducible impact. Include the affected component, prerequisites, exact steps, proof of impact and any safe reproduction details the security team needs.
  4. Submit privately through HackerOne. Security issues must be submitted through the official channel rather than posted publicly or sent through an unrelated support route.
  5. Wait for coordination. Public disclosure before the issue is resolved can make a report ineligible and can put users at risk.

Does WordPress pay for security bugs?

Sometimes. A qualifying report can receive a monetary reward, but HackerOne’s guidance makes clear that not every program pays and that reward decisions are discretionary. Automattic’s policy states that it makes the final decision and that awards generally go to the first reporter of a vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

The amounts below are nominal figures listed in Automattic’s policy for qualifying in-scope assets. They are not a promise, and the live policy should be checked because reward levels and scope can change.

Severity WordPress.com asset Everything else covered by that policy
Critical $1,000 $500
High $600 $300
Medium $300 $200
Low $100 $100

Severity, exploitability, duplication, report quality, asset eligibility and the program’s final assessment can affect the outcome. A report can be valid without receiving the nominal amount shown above.

Are WordPress plugins and themes included?

Not automatically. “WordPress bug bounty” is commonly used for two different situations:

  • Official WordPress HackerOne program: primarily WordPress Core, plus the related projects and infrastructure listed in its current policy.
  • Separate ecosystem or vendor programs: plugin and theme vulnerabilities may be handled by the individual developer or by a program that specifically covers those products.

Wordfence, for example, describes a separate Bug Bounty Program for impactful vulnerabilities in WordPress plugins and themes. Its rules, eligibility, reporting process, reward table, duplicate handling and disclosure terms are distinct from the official WordPress Core program. Always read the applicable program’s current scope before testing.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Special release incentives

WordPress has occasionally offered temporary bonuses tied to a particular release. During the WordPress 6.4 beta period, the security team announced that a new vulnerability reported after Beta 1 and before the final release candidate could receive double the normal bounty. That was a release-specific incentive, not a permanent doubling of WordPress rewards.

What makes a report useful

  • A clearly identified, in-scope asset and affected version or component.
  • Steps that another reviewer can reproduce without guesswork.
  • A precise explanation of confidentiality, integrity or availability impact.
  • Testing performed only with authorized accounts and data.
  • Private handling until the security team has coordinated a fix and disclosure.

Do not probe systems outside the policy, download unrelated personal information, change production data, or publish a proof of concept before resolution. Those actions can harm users and jeopardize eligibility.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

WordPress Core versus a plugin or theme: which channel should you use?

Question Official WordPress HackerOne program Plugin/theme or vendor program
Typical assets WordPress Core and policy-listed related projects or infrastructure Specific plugins, themes or vendor-controlled products listed by that program
Reporting platform HackerOne The developer’s stated channel, which may be HackerOne or another platform
Testing limits Defined by the current WordPress policy and applicable law Defined by the individual program’s rules
Reward decision Discretionary; Automattic makes the final decision for its policy Controlled by the separate program owner
Disclosure and duplicates Follow the live program policy and coordinated process Follow that vendor’s duplicate and disclosure terms

If the vulnerable code belongs to a third-party plugin or theme, identify its owner and consult that owner’s security policy rather than assuming the WordPress Core program applies.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.