VMP™ Security bug bounty program
Report vulnerabilities in WordPress plugins and themes, get credited in our hall of fame, and help protect hundreds of thousands of sites.
Program overview
Report a vulnerability in a WordPress plugin or theme and we coordinate the fix with the author, request a CVE where it qualifies, and credit you publicly on the hall of fame. New to security research or years in, every valid report counts.
One place to report
Report a vulnerability once and we handle the rest: triage, coordinated disclosure to the author, and a CVE request where it applies. You focus on the research; we run the process around it.
Public credit
Every validated finding earns severity-weighted points and a permanent place on the hall of fame. Points set your quarterly rank, and the top researchers each quarter receive a cash prize.
An open advisory database
Once a fix ships, your finding is published as a public advisory so other site owners can patch before attackers reach them.
Why take part
Right now you can:
- Report vulnerabilities in WordPress plugins and themes
- Get a CVE ID requested on your behalf for qualifying findings
- Earn points and build a public track record on the hall of fame
- Help secure plugins and themes that a large share of the web depends on
Program scope
What’s in scope
Vulnerabilities in WordPress plugins and themes, rated by severity from low through critical. Report against the latest version with clear reproduction steps.
Points by severity, plus quarterly cash prizes
We handle disclosure
We coordinate disclosure between you, the plugin or theme author, and the wider community, so a fix ships responsibly. You report; we manage the back-and-forth.
Published as an advisory
Once a fix is out, your finding is published as a public advisory so other site owners can patch before attackers reach them.
Points and recognition
Every validated advisory earns severity-weighted points and permanent public credit on the hall of fame, so your track record is easy to point to.
Program highlights
CVE IDs for eligible findings
For qualifying vulnerabilities, we request a CVE ID through the CVE Program on your behalf, giving your finding a public, citable identifier.
Points and hall of fame
Every validated finding earns severity-weighted points and a permanent, public place on the hall of fame.
Coordinated with the author
We coordinate the fix with the plugin or theme author, then publish your finding as a public advisory so others can patch.
Broad scope
The program spans a wide range of WordPress plugins and themes, so there’s room to contribute whatever your level.
Clear, published rules
Submission guidelines, scope, and disclosure timelines are written down, so you always know how a report is handled.
Researcher tiers
Planned. Formal tiers are a future addition. Today, standing is by points and your quarterly leaderboard rank, and the top researchers earn a cash prize. Here is how the tiers are planned to work.
Bronze
Getting started
- Hall-of-fame credit
- Community access
- Researcher profile
Silver
Consistent contributors
- Higher reward share (planned)
- Priority triage
- Enhanced profile
Gold
Proven expertise
- Higher reward multiplier (planned)
- Bonus opportunities (planned)
- Recognized profile
Platinum
Top contributors
- Top reward multiplier (planned)
- Early access to new features
- Direct line to the team
Rewards
How rewards work
Every validated finding earns severity-weighted points -- critical 40, high 20, medium 10, low 5 -- plus a place on the hall of fame and a CVE ID where it qualifies. Points set your quarterly leaderboard rank, and the top researchers each quarter receive a cash prize.
Points for every valid report
Points scale with the severity of what you find and add up on your public hall-of-fame standing.
A public advisory for each fix
Once the author patches, your finding is published as a citable advisory, with a CVE ID requested for qualifying vulnerabilities.
Submit a vulnerability
Found a security issue in a WordPress plugin or theme? Report it below. We coordinate disclosure with the vendor, credit you in the hall of fame, and request a CVE where it applies.
Submission received
Reference number:
Our security team typically responds within 1–3 business days.
Milestones
Recognition builds as you report valid findings and hit milestones, tracked through your points and hall-of-fame standing.
First report
Submit your first validated vulnerability
Critical find
Report a critical-severity vulnerability
Hot streak
Five valid reports in a single month
Community star
Pass 1,000 points on the hall of fame
Hall of fame
The researchers who report the most and the most serious findings. Report valid vulnerabilities and your name lands here.
Be the first name on the board -- report a valid vulnerability and get credited.
View the hall of fameFrequently asked questions
How reports are reviewed
Every report is reviewed and validated by the VMP™ Security threat-intelligence team, so severity ratings stay fair and consistent.
Validation
We reproduce each report, confirm its severity, and coordinate disclosure with the affected author before anything is published.
Coordinated disclosure
Once the author has had a chance to fix, the finding is published as a public advisory and credited to you on the hall of fame.
Ready to report a vulnerability?
Submit a finding, get a CVE where it qualifies, and earn your place on the hall of fame.