vulns.co
/
GKData.io MCP

Back to Platforms

WordPress Bug Bounty

Bug bounty for WordPress core and the open-source projects and sites listed on the HackerOne program.

Tags: vendor, hackerone, cms

Program model
Vendor on HackerOne
Regions
Global
Payout
Varies by program

Specialties: web, cms, api

How to approach it

Scope first. WordPress.com and the mobile apps are a different program. Read the in-scope table before testing a plugin or site.

  • Start from the HackerOne asset table, not from a random plugin in the directory.
  • Read the WordPress.org security page, then the program policy, before you test.

Official links