WordPress Bug Bounty
Bug bounty for WordPress core and the open-source projects and sites listed on the HackerOne program.
Tags: vendor, hackerone, cms
- Program model
- Vendor on HackerOne
- Regions
- Global
- Payout
- Varies by program
Specialties: web, cms, api
How to approach it
Scope first. WordPress.com and the mobile apps are a different program. Read the in-scope table before testing a plugin or site.
- Start from the HackerOne asset table, not from a random plugin in the directory.
- Read the WordPress.org security page, then the program policy, before you test.