Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A WordPress bug bounty program is a private, policy-governed way for security researchers to report vulnerabilities so they can be verified and fixed. WordPress identifies HackerOne as the reporting channel for Core issues; whether a valid report earns money depends on the active program rules and the team’s decision.

What the official WordPress program covers

WordPress’s security policy says its HackerOne program covers WordPress Core and a variety of related projects and infrastructure. Core is the central scope, but the policy defines which additional assets are eligible and which are excluded. Check the live policy before testing; a WordPress-related site or service is not automatically in scope.

The WordPress Security Team directs people who find a Core vulnerability to the official WordPress HackerOne program. Automattic separately directs reports about the WordPress, BuddyPress, and bbPress open-source projects to that same program.

How to report a vulnerability safely

  1. Confirm scope and rules. Read the current HackerOne policy and verify that the affected asset and testing method are permitted.
  2. Test responsibly. Automattic’s policy requires compliance with applicable law and use of your own test accounts. Do not access or modify another person’s data without consent.
  3. Document a reproducible impact. Explain the affected component, the steps needed to reproduce the issue, and the security consequence. Avoid exposing real user information.
  4. Submit privately through HackerOne. WordPress says security issues must be submitted via HackerOne. Do not publish details before the issue is resolved; premature disclosure can disqualify a report under the applicable policy.

Does WordPress pay for security bugs?

Potentially. A qualifying report may receive public recognition or a monetary reward, but payment is not guaranteed. HackerOne’s disclosure guidance notes that not every program pays a bounty, and reward decisions remain at the security team’s discretion. Eligibility, severity, asset, duplicate status, and the current policy all matter.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • No Starch Press
  • ABIS BOOK

Automattic’s live HackerOne policy lists these nominal awards for qualifying in-scope assets. The first amount in each row is for WordPress.com; the second is for everything else covered by that policy.

Severity WordPress.com Everything else
Critical $1,000 $500
High $600 $300
Medium $300 $200
Low $100 $100

The policy says Automattic makes the final award decision and generally awards a bounty to the first person to report a vulnerability. These listed amounts are policy figures, not a promise of payment, and may change; consult the current Automattic policy before relying on them.

Some incentives apply only during a release window

WordPress has offered temporary bonuses in addition to its usual policy. For example, the WordPress 6.4 Beta 1 announcement offered double the normal bounty for a new vulnerability reported after Beta 1 and before the final release candidate. That offer was tied to that release window; it is not a standing program rate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are plugins and themes included?

Not necessarily. The official WordPress HackerOne program focuses on Core and the additional projects or infrastructure explicitly listed in its policy. Third-party plugin and theme issues may be covered by the developer’s own disclosure process or a separate ecosystem program, rather than by WordPress’s Core channel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Wordfence, for example, describes a separate bug bounty program for WordPress plugins and themes, aimed at impactful vulnerabilities. Its scope and requirements are distinct from WordPress’s program. Before testing or reporting, identify the program responsible for the particular plugin or theme and follow its current rules.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.