A WordPress bug bounty program is a private, policy-governed way for security researchers to report vulnerabilities so they can be verified and fixed. WordPress identifies HackerOne as the reporting channel for Core issues; whether a valid report earns money depends on the active program rules and the team’s decision.
What the official WordPress program covers
WordPress’s security policy says its HackerOne program covers WordPress Core and a variety of related projects and infrastructure. Core is the central scope, but the policy defines which additional assets are eligible and which are excluded. Check the live policy before testing; a WordPress-related site or service is not automatically in scope.
The WordPress Security Team directs people who find a Core vulnerability to the official WordPress HackerOne program. Automattic separately directs reports about the WordPress, BuddyPress, and bbPress open-source projects to that same program.
How to report a vulnerability safely
- Confirm scope and rules. Read the current HackerOne policy and verify that the affected asset and testing method are permitted.
- Test responsibly. Automattic’s policy requires compliance with applicable law and use of your own test accounts. Do not access or modify another person’s data without consent.
- Document a reproducible impact. Explain the affected component, the steps needed to reproduce the issue, and the security consequence. Avoid exposing real user information.
- Submit privately through HackerOne. WordPress says security issues must be submitted via HackerOne. Do not publish details before the issue is resolved; premature disclosure can disqualify a report under the applicable policy.
Does WordPress pay for security bugs?
Potentially. A qualifying report may receive public recognition or a monetary reward, but payment is not guaranteed. HackerOne’s disclosure guidance notes that not every program pays a bounty, and reward decisions remain at the security team’s discretion. Eligibility, severity, asset, duplicate status, and the current policy all matter.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
- No Starch Press
- ABIS BOOK
Automattic’s live HackerOne policy lists these nominal awards for qualifying in-scope assets. The first amount in each row is for WordPress.com; the second is for everything else covered by that policy.
| Severity | WordPress.com | Everything else |
|---|---|---|
| Critical | $1,000 | $500 |
| High | $600 | $300 |
| Medium | $300 | $200 |
| Low | $100 | $100 |
The policy says Automattic makes the final award decision and generally awards a bounty to the first person to report a vulnerability. These listed amounts are policy figures, not a promise of payment, and may change; consult the current Automattic policy before relying on them.
Rank #2
Some incentives apply only during a release window
WordPress has offered temporary bonuses in addition to its usual policy. For example, the WordPress 6.4 Beta 1 announcement offered double the normal bounty for a new vulnerability reported after Beta 1 and before the final release candidate. That offer was tied to that release window; it is not a standing program rate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Are plugins and themes included?
Not necessarily. The official WordPress HackerOne program focuses on Core and the additional projects or infrastructure explicitly listed in its policy. Third-party plugin and theme issues may be covered by the developer’s own disclosure process or a separate ecosystem program, rather than by WordPress’s Core channel.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Wordfence, for example, describes a separate bug bounty program for WordPress plugins and themes, aimed at impactful vulnerabilities. Its scope and requirements are distinct from WordPress’s program. Before testing or reporting, identify the program responsible for the particular plugin or theme and follow its current rules.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

