*.buddypress.org,bbpress.org,profiles.wordpress.org· critical*.wordcamp.org· critical*.wordpress.net— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for WordPress.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 1036,
"average_time_to_first_program_response": null,
"average_time_to_report_resolved": null,
"handle": "wordpress",
"id": 0,
"managed_program": false,
"name": "WordPress",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 71,
"submission_state": "open",
"url": "https://hackerone.com/wordpress",
"website": "https://wordpress.org/",
"targets": {
"in_scope": [
{
"asset_identifier": "*.buddypress.org,bbpress.org,profiles.wordpress.org",
"asset_type": "WILDCARD",
"availability_requirement": "medium",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "*.trac.wordpress.org, *.svn.wordpress.org, *.git.wordpress.org, github.com/WordPress",
"asset_type": "SOURCE_CODE",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "**Do _not_ pentest Trac instances**, it's very annoying to clean up after. Setup a local environment instead; the custom source code is available via the Git command below, in the `trac.wordpress.org` subfolder. **If you ignore this you'll forfeit any bounty.**\n\nThe projects here are kept mostly for archival purposes and non-critical information disclosure will generally not be eligible for a bounty.\n\nOnly report vulnerabilities in our custom code, don't report vulnerabilities that only exist upstream in Trac itself. Report those directly to info@edgewall.com.\n\nAll source code that isn't behind authentication is intended to be public. The source code itself has `High` CVSS impact scores. The applications that manage the code (Trac, Git, SVN, etc) have `Low` scores, except for vulnerabilities that allow modifications to the source code.\n\nMost of the source code in these domains is contained in the \"meta\" repository: `git clone git://meta.git.wordpress.org/`",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "*.wordcamp.org",
"asset_type": "WILDCARD",
"availability_requirement": "medium",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "*.wordpress.net",
"asset_type": "WILDCARD",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "For bounty purposes, only the following *.wordpress.net sites are eligible:\n-jobs\n-playground",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.wordpress.org",
"asset_type": "WILDCARD",
"availability_requirement": "medium",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "All wordpress.org domains that **are not listed in other assets**, including (but not limited to) the following:\n* login.wordpress.org\n* developer.wordpress.org\n* make.wordpress.org\n* translate.wordpress.org\n* global.wordpress.org, {locale}.wordpress.org (e.g., de.wordpress.org, es-mx.wordpress.org)\n* learn.wordpress.org",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "BuddyPress Core",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Download source code from: https://buddypress.org/download/",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "GlotPress",
"asset_type": "SOURCE_CODE",
"availability_requirement": "medium",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "All code located under [the GlotPress organization](https://github.com/GlotPress/) on GitHub.\n\nThe most important target is the `glotpress-wp` repository. Other repositories are in scope, but may have a lower importance.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Gutenberg",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Download source code from https://github.com/WordPress/gutenberg",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Official WordPress plugins",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Only the following plugins that are officially maintained by WordPress.org are in scope.\n\n* [Classic Editor](https://wordpress.org/plugins/classic-editor/)\n* [Create Block Theme](https://wordpress.org/plugins/create-block-theme/)\n* [Secure Custom Fields](https://wordpress.org/plugins/secure-custom-fields/)\n* [SQLite Database Integration](https://wordpress.org/plugins/sqlite-database-integration/)\n\nAny other plugins, including those that list `wordpressdotorg` as a contributor or developer, are not in scope.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "WP-CLI",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "All code located under [the WP-CLI organization](https://github.com/wp-cli) on GitHub.\n\nThe most important targets are the main `wp-cli` repository, and any repositories for commands that are bundled with the distributed `wp-cli` source code, like `cache-command`, `scaffold-command`, etc.\n\nOther repositories are in scope, but may have a lower importance.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "WordPress Core",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Download source code from: https://wordpress.org/download/source/",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "api.wordpress.org",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "bbPress Core",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Download source code from: https://bbpress.org/download/",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "codex.wordpress.org,codex.bbpress.org,codex.buddypress.org",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "These are wikis, they're intended to be freely edited by anonymous users. We are not interested in vulnerabilities unless they have a severe impact.",
"integrity_requirement": "low",
"max_severity": "medium"
},
{
"asset_identifier": "doaction.org",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "mercantile.wordpress.org",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "This site runs uses [the WooCommerce plugin](https://woocommerce.com/), but we don't accept reports for that. We only accept reports for our custom code. If you find any vulnerabilities that are also present in WooCommerce itself, please [report them to Automattic](/automattic).\n\nPlease don't submit test orders (especially automated ones). They don't test any of our custom code, and are a pain to clean up.\n\nAdditionally, price manipulation is a common invalid report, please see #682344.",
"integrity_requirement": "low",
"max_severity": "medium"
},
{
"asset_identifier": "planet.wordpress.org",
"asset_type": "URL",
"availability_requirement": "medium",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "wordpressfoundation.org",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "low",
"max_severity": "medium"
}
],
"out_of_scope": [
{
"asset_identifier": "*.wordpress.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "All WordPress.com vulnerabilities should be reported to [Automattic's HackerOne program](https://hackerone.com/automattic). \n\n**WordPress.com vulnerabilities reported here will be marked as `Not Applicable`.**",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "335703880",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "**Please, report vulnerabilities for the WordPress mobile apps through the [Automattic HackerOne page](/automattic).**\n",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Archived GitHub repositories",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Archived code repositories (e.g. in GitHub) are out of scope, unless you have verified that code from it is imported and actively being used.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Digital Ocean, AWS, etc",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Unless otherwise noted, we own and operate dedicated servers, rather than using services like AWS, Digital Ocean, etc. Third-parties frequently create S3 buckets, droplets, etc that have security issues, and have \"WordPress\" in the name. These are not ours, and reports about them will be closed as `Not Applicable`.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://github.com/wordpress-mobile/",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "**Please, report vulnerabilities for the WordPress mobile apps through the [Automattic HackerOne page](/automattic).**\n",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "irclogs.wordpress.org",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "These are public logs of very old conversations. We are not interested in vulnerabilities unless they have a severe impact (e.g., RCE, XSS, modifying the logs, etc). DoS is not severe in this case.",
"integrity_requirement": "low",
"max_severity": "none"
},
{
"asset_identifier": "lists.wordpress.org",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "We are not interested in vulnerabilities unless they have a severe impact.",
"integrity_requirement": "low",
"max_severity": "none"
},
{
"asset_identifier": "munin-*.wordpress.org",
"asset_type": "WILDCARD",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "We are not interested in vulnerabilities unless they have a severe impact (e.g., RCE, SSRF). Metrics data is intentionally made public.",
"integrity_requirement": "low",
"max_severity": "none"
},
{
"asset_identifier": "org.wordpress.android",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "**Please, report vulnerabilities for the WordPress mobile apps through the [Automattic HackerOne page](/automattic).**\n",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "status.wordpress.org,glotpress.blog,wordpress.tv",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "These are hosted on WordPress.com and we don't have access to modify the code, servers, etc. Check [Automattic's HackerOne program](https://hackerone.com/automattic) for details on reporting vulnerabilities with WordPress.com sites.",
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}api.wordpress.org· criticalcodex.wordpress.org,codex.bbpress.org,codex.buddypress.org· mediumdoaction.org· criticalmercantile.wordpress.org· mediumplanet.wordpress.org· criticalwordpressfoundation.org· medium*.trac.wordpress.org, *.svn.wordpr…ess.org, github.com/WordPress· criticalBuddyPress Core· criticalGlotPress· criticalGutenberg· criticalOfficial WordPress plugins· criticalWP-CLI· criticalWordPress Core· criticalbbPress Core· critical*.wordpress.communin-*.wordpress.orgirclogs.wordpress.orglists.wordpress.orgstatus.wordpress.org,glotpress.blog,wordpress.tv335703880Archived GitHub repositoriesDigital Ocean, AWS, etcorg.wordpress.android