VMP™ Security bug bounty program

Report vulnerabilities in WordPress plugins and themes, get credited in our hall of fame, and help protect hundreds of thousands of sites.

Program overview

Report a vulnerability in a WordPress plugin or theme and we coordinate the fix with the author, request a CVE where it qualifies, and credit you publicly on the hall of fame. New to security research or years in, every valid report counts.

One place to report

Report a vulnerability once and we handle the rest: triage, coordinated disclosure to the author, and a CVE request where it applies. You focus on the research; we run the process around it.

Public credit

Every validated finding earns severity-weighted points and a permanent place on the hall of fame. Points set your quarterly rank, and the top researchers each quarter receive a cash prize.

An open advisory database

Once a fix ships, your finding is published as a public advisory so other site owners can patch before attackers reach them.

Why take part

Right now you can:

  • Report vulnerabilities in WordPress plugins and themes
  • Get a CVE ID requested on your behalf for qualifying findings
  • Earn points and build a public track record on the hall of fame
  • Help secure plugins and themes that a large share of the web depends on

Program scope

What’s in scope

Vulnerabilities in WordPress plugins and themes, rated by severity from low through critical. Report against the latest version with clear reproduction steps.

Points by severity, plus quarterly cash prizes

We handle disclosure

We coordinate disclosure between you, the plugin or theme author, and the wider community, so a fix ships responsibly. You report; we manage the back-and-forth.

Published as an advisory

Once a fix is out, your finding is published as a public advisory so other site owners can patch before attackers reach them.

Points and recognition

Every validated advisory earns severity-weighted points and permanent public credit on the hall of fame, so your track record is easy to point to.

Program highlights

Recognition

CVE IDs for eligible findings

For qualifying vulnerabilities, we request a CVE ID through the CVE Program on your behalf, giving your finding a public, citable identifier.

Standing

Points and hall of fame

Every validated finding earns severity-weighted points and a permanent, public place on the hall of fame.

Disclosure

Coordinated with the author

We coordinate the fix with the plugin or theme author, then publish your finding as a public advisory so others can patch.

Broad scope

The program spans a wide range of WordPress plugins and themes, so there’s room to contribute whatever your level.

Clear, published rules

Submission guidelines, scope, and disclosure timelines are written down, so you always know how a report is handled.

Researcher tiers

Planned. Formal tiers are a future addition. Today, standing is by points and your quarterly leaderboard rank, and the top researchers earn a cash prize. Here is how the tiers are planned to work.

Bronze

Getting started

  • Hall-of-fame credit
  • Community access
  • Researcher profile

Silver

Consistent contributors

  • Higher reward share (planned)
  • Priority triage
  • Enhanced profile

Gold

Proven expertise

  • Higher reward multiplier (planned)
  • Bonus opportunities (planned)
  • Recognized profile

Platinum

Top contributors

  • Top reward multiplier (planned)
  • Early access to new features
  • Direct line to the team

Rewards

How rewards work

Every validated finding earns severity-weighted points -- critical 40, high 20, medium 10, low 5 -- plus a place on the hall of fame and a CVE ID where it qualifies. Points set your quarterly leaderboard rank, and the top researchers each quarter receive a cash prize.

Points for every valid report

Points scale with the severity of what you find and add up on your public hall-of-fame standing.

A public advisory for each fix

Once the author patches, your finding is published as a citable advisory, with a CVE ID requested for qualifying vulnerabilities.

Submit a vulnerability

Found a security issue in a WordPress plugin or theme? Report it below. We coordinate disclosure with the vendor, credit you in the hall of fame, and request a CVE where it applies.

Submission received

Reference number:
Our security team typically responds within 1–3 business days.

Browse the vulnerability database

CONTACT DETAILS

SOFTWARE DETAILS

The wordpress.org directory slug of the affected software.

VULNERABILITY DETAILS

Describe the vulnerability in detail: steps to reproduce, affected functionality, and potential impact. Max 10,000 characters.

PROOF OF CONCEPT

MORE DETAILS (OPTIONAL)


If another researcher referred you, enter their leaderboard handle — they earn a small one-level bonus. See how it works on the rewards page.

We store your name, email, and IP address only to process this report and coordinate the fix. Records for rejected or duplicate reports are purged after 90 days, and IP addresses are anonymized once triage is complete.

All submissions are reviewed by the VMP™ Security threat-intelligence team.

Milestones

Recognition builds as you report valid findings and hit milestones, tracked through your points and hall-of-fame standing.

First report

Submit your first validated vulnerability

Critical find

Report a critical-severity vulnerability

Hot streak

Five valid reports in a single month

Community star

Pass 1,000 points on the hall of fame

Hall of fame

The researchers who report the most and the most serious findings. Report valid vulnerabilities and your name lands here.

Be the first name on the board -- report a valid vulnerability and get credited.

View the hall of fame

Frequently asked questions

Submit your finding through the form on this page. Include the affected plugin or theme, its version, and clear steps to reproduce. We review every report and reply with next steps.

Valid vulnerabilities in WordPress plugins and themes — XSS, SQL injection, CSRF, authentication bypass, and similar classes. Report against the latest version with clear reproduction steps.

You earn points by severity: critical 40, high 20, medium 10, low 5. Points set your quarterly leaderboard rank, and the top researchers each quarter receive a cash prize. Every valid report also earns hall-of-fame credit and a CVE where it applies.

Yes — the program is open. Use the form on this page to report a finding, and track recognized researchers on the hall of fame.

How reports are reviewed

Every report is reviewed and validated by the VMP™ Security threat-intelligence team, so severity ratings stay fair and consistent.

Validation

We reproduce each report, confirm its severity, and coordinate disclosure with the affected author before anything is published.

Coordinated disclosure

Once the author has had a chance to fix, the finding is published as a public advisory and credited to you on the hall of fame.

Ready to report a vulnerability?

Submit a finding, get a CVE where it qualifies, and earn your place on the hall of fame.