Wordfence Bug Bounty Program — Terms and Conditions

These Wordfence Bug Bounty Program (“Program”) Terms and Conditions (“Terms and Conditions”), describe the terms and conditions of your participation in the Program and are a binding agreement between you (the “Researcher”) and Defiant, Inc., a Delaware corporation, and its officers, directors, employees, agents, licensees, independent contractors, successors, and assigns are referred to herein collectively as “Company.”

For the purposes of these Terms and Conditions, a “Vulnerability” is any information submitted through the Wordfence Vulnerability Submission Form.

Researchers ("you", "your") may submit Vulnerabilities of any type for CVE assignment via the Wordfence Vulnerability Submission Form located at https://www.wordfence.com/threat-intel/vulnerabilities/submit, or our CVE request form located at https://www.wordfence.com/request-cve/. Independent Researchers do not need to participate in the Program in order to report Vulnerabilities to Company or request a CVE ID. If you would like to report a Vulnerability to Company for CVE assignment, or addition to the Wordfence Intelligence Vulnerability database, please use the Wordfence Vulnerability Submission Form.

To participate in the Program, Researchers must accept and follow these Terms and Conditions. Company reserves the right to modify the scope, rules, and vulnerability reward payouts at any time. Company also reserves the right to suspend or terminate the Program, in whole or in part, at any time, for any reason, with or without notice to Researchers. These Terms and Conditions are incorporated into and made part of the Wordfence Terms of Service by reference. If you do not agree to these Terms and Conditions, do not submit Vulnerabilities through the Program.

1. Wordfence Bug Bounty Program Rules

The Researcher agrees as follows:

  1. Researcher Accounts and General Rules

    1. To participate in the Program, Researchers must create a Researcher Account and be authenticated at the time the Researcher submits the Vulnerability. To create a Researcher Account, please visit: https://www.wordfence.com/threat-intel/researcher-register.
    2. When you submit a Vulnerability, the Researcher Profile information you provide in connection with your Researcher Account, including your name, alias, display name, X (formerly Twitter) handle, Facebook url, LinkedIn url, website address, and biographical information may be displayed publicly and shared with Company service providers and other Researchers.
    3. Company must be the only organization a Researcher submits the Vulnerability to, and the Vulnerability must not be previously disclosed elsewhere, in order to be eligible for Reward Payment as set forth in the Wordfence Bug Bounty Reward Payment Schedule.
    4. You will not publicly disclose any of the Vulnerability’s details until (a) Company has completed the Responsible Disclosure process set forth at https://www.wordfence.com/blog/2021/07/youve-found-a-vulnerability-now-what-a-guide-to-responsible-disclosure/ and (b) the CVE has been made public. Company will contact you when these two activities are complete.
      1. Vulnerabilities will be considered confidential until they have been published in the Wordfence Intelligence vulnerability database.
      2. If you share details of the Vulnerability with a third party while the company is conducting the responsible disclosure process, you will be given a warning for the first offense. Additional offenses may result in you being banned from participating in the program.
  2. Eligibility and Reward Payment

    1. For any submitted Vulnerability to be eligible for Reward Payment, the Vulnerability must be within the bug bounty program scope outlined in the section titled “Bug Bounty Program Scope” below, and the Vulnerability must be Validated as set forth in Section 2(b) of the Wordfence Bug Bounty Program Submission Release.
    2. Any Vulnerability may be rejected or returned to the Researcher if it is missing complete details that help validate and confirm the existence of the Vulnerability.
    3. A researcher will be considered a New Researcher upon registering an account for participating in the Bug Bounty Program. New Researchers are considered those who have submitted fewer than 10 validated submissions, and are not in the Resourceful Researcher or 1337 Researcher tier. New Researchers can only have a total of 15 pending Vulnerability Reports submitted at any given time, with up to 10 of those being considered in-scope for a bounty reward. Once a New Researcher has submitted the limit of 15 pending Vulnerability Submissions, they will no longer be able to submit any new Vulnerability Reports until a pending report has been triaged.
    4. A Standard Researcher can only have 10 pending Vulnerability submissions open at any given time, unless they are a Researcher in one of our additional researcher tiers. 1337 Wordfence Vulnerability Researchers can have 50 pending Vulnerability submissions open at any given time, and Resourceful Researchers can have 25 pending Vulnerability submissions open at any given time.
    5. Vulnerabilities dependent upon one or more additional vulnerabilities to exploit are not eligible for Reward Payment, unless the vulnerable software and/or the current version of WordPress Core include(s) all vulnerabilities required to perform a successful exploit.
    6. Vulnerabilities that require more than one CVE assignment may not be eligible for more than one Reward Payment (as set forth and defined in the Wordfence Bug Bounty Program Submission Release). The Reward Payment will be awarded for the higher paying CVE’s vulnerability type.
      1. Example: Missing Authorization vulnerabilities that are also vulnerable to Cross-Site Request Forgery are only eligible for the missing authorization Reward Payment, however, the report may receive two CVEs depending on how the two issues were patched.
    7. A Vulnerability that affects multiple plugins, themes, libraries, or other software components with the same vulnerable code will be awarded a Reward Payment for the base rate along with a multiplier depending on how many components are affected, as set forth in the Wordfence Bug Bounty Reward Payment Schedule.
    8. Vulnerabilities that require high-level privileges to exploit (PR:H), such as access to a user account with the administrator or editor role, may receive a CVE ID, but are not eligible for a Reward Payment.
    9. At Company’s sole discretion, Vulnerability submissions may be eligible for bonuses to award exceptional work.
    10. In the event of two or more Researchers submitting the same Vulnerability in the same component, the Researcher who submitted first will be the one eligible to receive Reward Payment.
    11. Vulnerabilities that have the same code-base as a previously disclosed Vulnerability that received Reward Payment will not be awarded any additional Reward Payment.
    12. Only one critical impact bounty will be awarded to the first submitting researcher for any given vulnerability type and impact reported and present in the most current version of the affected software, regardless of any additional pieces of functionality being affected and submitted by additional researchers. For example, if researcher A submits a Contributor-level Stored Cross-Site Scripting vulnerability in plugin “ABC” and then three other researchers submit Contributor-level Stored Cross-Site Scripting vulnerabilities in plugin “ABC” in three different widgets, only researcher A will be granted a critical impact bounty award. The subsequent researchers may be awarded a lower impact bounty at Defiant's discretion. However, if one of the other researchers submits a different type of Stored Cross-Site Scripting, such as Subscriber-level Stored Cross-Site Scripting, they would be eligible for a critical impact bounty.
    13. Bypasses to patches in vulnerabilities originally reported through the bug bounty program are not eligible for a full bounty reward within 10 version releases, but may be eligible for a reduced bounty on a case-by-case basis unless we suspect there was gaming involved.
    14. Once a PHP Object Injection gadget has been discovered and reported in a plugin/theme, only the first PHP Object Injection vulnerability reported leveraging that gadget will be eligible for a bounty at the full rate of impact (i.e. RCE). Any subsequent PHP Object Injection vulnerabilities leveraging the same gadget, and submitted within 30 versions of the last reported PHP Object Injection, will be awarded at the PHP Object Injection w/out Gadget rate unless a new gadget is discovered and demonstrated.
    15. A vulnerability being assigned a CVE ID is not a guarantee that the vulnerability will be in-scope for a reward payment.
  3. Wordfence Refer-A-Researcher Program

    1. Some Researchers may be eligible to participate in the Wordfence Refer-A-Researcher Program to earn bonuses for referring Researchers. The following terms and conditions apply to the Wordfence Refer-A-Researcher Program:
    2. Eligibility Criteria and Application
      1. Researchers must be registered and approved with the Wordfence Bug Bounty Program for a minimum of one month.
      2. Researchers must have submitted at least ten validated in-scope vulnerabilities.
      3. Company reserves the right to approve or deny any application to participate in the Wordfence Refer-A-Researcher Program at its discretion.
      4. Any Researcher found violating the terms will be banned from the Wordfence Refer-A-Researcher Program.
      5. Both the Referring and Referred Researchers may face bans or temporary restrictions from the Bug Bounty Program at the discretion of Company.
    3. Referral Process
      1. Upon approval, Researchers (“Referring Researchers”) will receive a referral link to share with potential researchers (“Referred Researchers”).
      2. Referred Researchers must register using the Referring Researcher’s referral link for the Referring Researcher to earn a bonus.
    4. Bonus Structure and Payment
      1. If a Referred Researcher submits five Vulnerabilities that are accepted within their first year of the Referred Researcher’s registration, the Referring Researcher is eligible to receive a bonus of 20% of the total value of the first five Reward Payments that the Referred Researcher earned.
      2. Bonuses will be paid in a single installment once all five Vulnerabilities are accepted and according to the Wordfence Bug Bounty Reward Payment Schedule.
  4. Prohibited Acts, Banning, and Restriction

    1. If we suspect an individual is using automated tools to perform bulk vulnerability discovery, we reserve the right to restrict the level of Reward Payments that individual is eligible for.
    2. Developers may not report Vulnerabilities in their own software.
    3. Company may terminate, ban, or restrict a Researcher for any reason at the sole discretion of Company.
    4. If a Researcher creates a second account in an attempt to bypass any of these rules or restrictions, both accounts may be permanently banned.
    5. Researchers violating any of these Terms and Conditions may be restricted or banned from the Program and be unable to submit Vulnerabilities.
    6. If a Researcher submits more than 2 low-quality AI Hallucinated reports (for example, a vulnerability report that describes a vulnerability that does not exist in the codebase, follows typical AI-generated structure, or includes a proof of concept that has not been tested and does not function as described) over a period of 30 days, the Researcher’s ability to submit Vulnerabilities will be restricted, at the Company’s discretion, for the next 30 days.
      • After the initial 2 AI Hallucinated reports, if another 2 AI Hallucinated reports are submitted, then the Researcher may be permanently banned from participating in the Program.
    7. If a Researcher submits more than 5 false positive, low-quality (for example, simply outputting the results of a security scanner), or out-of-scope Vulnerabilities over a period of 7 days, the Researcher’s ability to submit Vulnerabilities will be restricted, at Company’s discretion, for the next 7 days.
      1. After the first 5 false positive reports, if a Researcher submits more than 5 false positive, low-quality (for example, simply outputting the results of a security scanner), or out-of-scope Vulnerabilities over a subsequent period of 7 days, the Researcher’s ability to submit Vulnerabilities will be restricted, at Company’s discretion, for the next 14 days.
      2. After the first 10 false positive reports, if a Researcher submits more than 10 false positive, low-quality (for example, simply outputting the results of a security scanner), or out-of-scope Vulnerabilities over a subsequent period of 14 days, the Researcher’s ability to submit Vulnerabilities will be restricted, at Company’s discretion, for the next 30 days.
      3. After 30 false positive, low-quality, or out-of-scope Vulnerability submissions, the Researcher may be permanently banned from participating in the Program.
    8. If we suspect a researcher is attempting to game the Bug Bounty Program to bypass current rules and bounty reward criteria, we may restrict or ban the researcher from being able to participate in the program. Examples of gaming include a) withholding vulnerability information from a Vulnerability Submission in attempt to earn an additional bounty by submitting additional information (i.e. a bypass) in a subsequent new report when the initial reported vulnerability is suspected to be patched b) working as a team to submit multiple affected components of the same vulnerability type in a single plugin through different reports to earn a bounty for each affected component (i.e. widget).
    9. If a New Researcher submits 10 out of scope reports in a period of 7 days, they will be throttled and no longer able to submit any more reports for a period of 7 days.
    10. If artificial intelligence (AI) tools are used at any stage to generate or assist with a vulnerability report, this must be accurately disclosed in the vulnerability submission form. Misrepresenting or failing to disclose the use of AI tools may result in the submission being deemed ineligible for a reward and may lead to a permanent ban from the Program.
    11. Researchers are expected to classify the severity and category of their submissions correctly. A pattern of misclassifying vulnerabilities in an attempt to obtain priority triage or preferential queue placement may result in suspension or permanent removal from the Program.
    12. Vulnerability reports generated using AI must be manually verified by the submitting Researcher prior to submission. Submitting AI-generated, or other, reports without proper manual validation may result in the Researcher being restricted or permanently banned from the Program.
    13. The automated use of AI or other tools to generate and submit vulnerability reports in bulk is strictly prohibited. Accounts found engaging in automated or large-scale AI-generated submissions may be suspended or permanently banned from the Program.
    14. Referring and Referred Researchers are prohibited from:
      1. Creating multiple accounts to submit vulnerabilities and earn bonuses; or
      2. Soliciting others to create accounts and submit vulnerabilities on their behalf.

2. Bug Bounty Program Scope

  1. Assets Considered In Scope

    1. High Threat Vulnerabilities
      All WordPress plugins and themes that can be run locally, both free and premium, with >= 25 active installations are in scope for all researchers for a select list of high threat vulnerabilities when exploitable by unauthenticated or low-level authenticated (Subscriber) attackers. These vulnerabilities are exclusively listed here:
      • Arbitrary PHP File Upload
      • Arbitrary PHP File Read
      • Arbitrary PHP File Deletion
      • Arbitrary Options Update
      • Remote Code Execution
      • Authentication Bypass to Admin
      • Privilege Escalation to Admin
      Note: High Threat Vulnerabilities in plugins and themes with between 25 and 999 Active Installations must be listed in the WordPress.org Plugin Repository to be in-scope.
    2. Common and Dangerous Vulnerabilities
      All WordPress plugins and themes that can be run locally, both free and premium, with >= 500 active installations are in scope for all researchers for a select list of common and dangerous vulnerabilities when exploitable by unauthenticated or low-level authenticated (Subscriber) attackers. These vulnerabilities are exclusively listed here:
      • Stored Cross-Site Scripting
      • SQL Injection
      Note: Common and Dangerous Vulnerabilities in plugins and themes with between 500 and 999 Active Installations must be listed in the WordPress.org Plugin Repository to be in-scope.
    3. All Remaining In-Scope Vulnerabilities
      All WordPress plugins and themes that can be run locally, both free and premium, with >=50,000 active installations are in scope for all Researchers, with a few exceptions detailed in the out-of-scope section. If you are a “1337 Wordfence Vulnerability Researcher” (defined below) all WordPress plugins and themes that can be run locally, both free and premium, with >=500 active installations are in scope, with a few exceptions detailed in the out-of-scope section. If you are in our “Resourceful Researcher” researcher tier (defined below) all WordPress plugins and themes that can be run locally, both free and premium, with >=10,000 active installations are in scope, with a few exceptions detailed in the out-of-scope section.
  2. Assets Considered Out of Scope

    1. WordPress Core is considered out of scope for the Program, however, we may still assign a CVE ID to any Vulnerability discovered in core.
    2. Software, services, and developers that maintain a publicly published bug bounty or responsible disclosure program, managed directly by the developer, are considered out-of-scope for the Program (“Out-Of-Scope Assets”). A list of Out-Of-Scope Assets is set forth below and may be updated by Defiant from time-to-time (the “Out-Of-Scope Asset List”). Whereas Defiant monitors software, services, and developers to determine if they maintain their own bug bounty or responsible disclosure program, new programs are continually released and we cannot guarantee that we have identified and included all such programs in the Out-Of-Scope Asset List. Defiant will not pay Reward Payments for Vulnerabilities you report if the Vulnerability relates to an Out-Of-Scope Asset, regardless of whether the Out-Of-Scope Asset is included on the Out-Of-Scope Asset List. If you are unsure if you can report a Vulnerability to us, and potentially earn a Reward Payment, please contact us at wfi-support@wordfence.com.

      For avoidance of doubt, any software listed under a competing WordPress Vulnerability Disclosure Program (VDP), Bug Bounty Program, or vulnerability database is not considered out-of-scope to the extent that the Vulnerability is reported directly to us and not a competitor.

      Out-Of-Scope Asset List:
    3. Plugins or Themes that are closed to downloads or sales are not in scope, unless the closure reason was due to a Vulnerability the reporting Researcher found and responsibly disclosed, and the Researcher has adequate proof they were the one who found and reported the issue.
    4. Any web service, application, or endpoint associated with a WordPress plugin or theme that is not run locally (such as an API running on a plugin vendor’s website) is considered out of scope. For the avoidance of doubt, this includes any vulnerability that is exploitable via a WordPress plugin or theme, but can be patched on an external server or service, and is not within the WordPress plugin or theme itself.
    5. WordPress plugins or themes not downloadable from WordPress.org with fewer than 1,000 estimated active installations or sales.
  3. Vulnerabilities Considered In-Scope

    All issues in WordPress Plugins and Themes with a considerable impact to the confidentiality, integrity, and availability of a WordPress site are considered in scope of this program as long as they do not require high level permissions, such as administrator or editor (i.e. CVSSv3.1 PR:H) to exploit. The following is a list of some common vulnerabilities that will be accepted.

    • Stored Cross-Site Scripting
    • Reflected Cross-Site Scripting
    • Cross-Site Request Forgery, that has a considerable impact on a site's security
    • Missing Authorization, that leads to a considerable impact on a site's security
    • Arbitrary Content Deletion
    • SQL Injection
    • Insecure Direct Object Reference
    • Arbitrary File Upload
    • Arbitrary File Download/Read
    • Arbitrary File Deletion
    • Local File Include/Remote File Include
    • Directory Traversal
    • Privilege Escalation to Admin
    • Privilege Escalation to Non-Admin
    • Authentication Bypass to Admin
    • Authentication Bypass to Non-Admin
    • Remote Code Execution/Code Injection
    • Information Disclosure
    • PHP Object Injection
    • Intentional Backdoors Added by Developers that are Accessible by Threat Actors
  4. Vulnerabilities Considered Out of Scope

    Vulnerabilities that have a minimal impact on the security of WordPress sites, or are unlikely to be successfully exploited in the wild will likely be considered out of scope for the program and will be rejected for CVE assignment upon submission.

    • Anything listed in our 'Common False Positive Reports' is automatically considered Out of Scope as they are not considered valid vulnerabilities
    • Business Logic Flaws where the demonstrated impact is primarily business-related rather than security-related. This includes, but is not limited to, issues such as payment bypasses, pricing manipulation, discount or coupon abuse, order workflow abuse, or other logic flaws that affect revenue, transactions, or business operations without introducing a direct security impact.
    • All DoS Vulnerabilities
    • Software containing vulnerable packages or dependencies that are not verifiably exploitable in that plugin or theme
    • Any Vulnerability requiring PR:H to Exploit. Administrator, Editor, and Shop Manager roles, along with any other role that has the unfiltered_html capability fall into this category.
    • Any Vulnerability requiring mid-level authentication to exploit. This includes Contributor and Author roles, along with any other role that needs to be granted by an administrator (i.e. not a common default registration role).
    • Open Redirect
    • Server-Side Request Forgery
    • Vulnerabilities dependent on successfully exploiting a race condition that is not easily replicable in a common configuration
    • Cache Poisoning, where this is not a considerable and demonstrable impact to site's security
    • Server-Side Request Forgery via DNS Rebinding (i.e. if wp_safe_remote_* or wp_http_validate_url() is in use, we do not consider the issue a valid SSRF vulnerability)
    • API Key Updates/Overwrites/Reads
    • Vulnerabilities that can only be exploited by an administrator explicitly granting access to a lower-privileged user where the likelihood of an administrator granting access is minimal or the administrator is granting access to functionality and features that can be abused
    • Vulnerabilities that require excessive brute force to exploit. Please note we may accept vulnerabilities as in scope where brute force is required and the likelihood of success is relatively high. Scope eligibility will be determined on a case-by-case basis.
    • Private/Hidden/Draft/Pending/Password Protected Post Access

    The list of 'Common False Positive Reports' is as follows:

    The following issues are frequently reported to our program but are not considered valid vulnerabilities and are routinely rejected. This list is not exhaustive and there may be other issues that we reject, these are just some of the most common issues we reject. Please do not submit reports for the following:

    • Low-Impact or Theoretical Issues
      • Theoretical vulnerabilities
      • Issues that lead to username enumeration
      • Lack of HTTP security headers
      • Clickjacking
      • Full path disclosure
      • Coupon code exposure
      • Wishlist updates
      • Google Maps API key access
      • Endpoints without brute-force or rate limiting protections (rate limiting is considered a server-side control)
      • Any vulnerability with a CVSS 3.1 score lower than 4.0 that cannot be leveraged to achieve a higher impact
    • Injection & Client-Side Issues (Non-Exploitable/Low Impact)
      • CSV Injection
      • CSS Injection
      • HTML Injection
      • Self Cross-Site Scripting (i.e. the payload is not stored and only rendered upon the initial action)
      • Reflected Cross-Site Scripting via headers
      • Cross-Site Scripting via SVG file uploads
      • File uploads containing embedded client-side scripts or macros (e.g., XSS in PDFs)
      • Malicious content stored in safe file types (e.g., PHP code inside a .jpg file)
      • Double extension file upload attacks (e.g., .php.png)
      • Safe filetype uploads (e.g., .jpg, .png) where upload functionality is intentional
    • Authentication, Authorization & Access Control (Expected or Intentional Behavior)
      • IP Spoofing
      • CAPTCHA bypasses
      • CORS issues
      • Tabnabbing
      • TOCTOU
      • Dismissing notices via CSRF or missing authorization
      • Cross-Site Request Forgery:
        • On unauthenticated forms with no sensitive actions
        • On read-only actions
      • Missing authorization where:
        • A valid nonce protects the action
        • The nonce is not exposed to lower-privileged users
      • Access keys or tokens used for authorization when adequately secure
      • Arbitrary shortcode execution by Contributor-level users or higher
      • High-level (Administrator, Editor, Shop Manager) XSS requiring unfiltered_html
      • Intentional functionality restricted to administrators (e.g., PHP snippet plugins, tracking script insertion)
      • Intentional functionality where scope is appropriately limited (i.e. user can submit a post with a featured image due to the plugin enabling such functionality as a well documented feature)
      • User registration bypass where registration is intentionally enabled through the software functionality or does not lead to privilege escalation
      • Unlimited voting, liking, or counting issues (i.e. a page counter where the count can be increased by several requests)
      • 2 Factor Authentication Bypasses
      • Missing authorization without a consequential confidentiality, integrity, or availability impact.
    • Environmental/Configuration-Based Issues
      • Vulnerabilities only exploitable on EOL software (PHP, MySQL, Apache, Nginx, OpenSSL, etc.)
      • Any SQL injection requiring wp_magic_quotes to be disabled
      • Vulnerabilities requiring local server access
      • Vulnerabilities requiring unsafe PHP configuration changes (e.g., enabling allow_url_fopen)
      • Secrets stored in plaintext that cannot be exploited through another vulnerability
      • Uploaded files in publicly accessible directories where exposure does not lead to site compromise
      • Software containing vulnerable dependencies that are not verifiably exploitable within the plugin or theme
      • Information exposed when WP_DEBUG is enabled.
      • Vulnerabilities dependent on an administrator misconfiguring or insecurely configuring their settings or environment.
    • Browser Version Requirements
      • Vulnerabilities that only affect users of outdated or unpatched browsers (defined as two stable versions behind the latest release.)

3. 1337 Wordfence Vulnerability Researcher Program

The 1337 Wordfence Vulnerability Researcher Program is a program designed to incentivize the most high-quality Researchers contributing to the security of the WordPress ecosystem. Once a Researcher has demonstrated authenticity and meaningful research, by meeting the outlined criteria, they will be awarded the “1337 Wordfence Vulnerability Researcher” status that will add a flag to their Researcher profile and unlock additional capabilities as a WordPress security Researcher, such as the ability to earn Reward Payments for lower install count software and a bonus on all reported Vulnerabilities.

  1. Eligibility for the 1337 Wordfence Vulnerability Researcher Program

    To be considered for “1337 Wordfence Vulnerability Researcher” status, a Researcher must meet and maintain the following requirements.

    1. The Researcher must complete at least one of the following:
      • Discover and submit 5 or more Critical Severity, High Impact (i.e. plugin/theme with over 50,000 Active Installations) Vulnerabilities with high quality reports.

        Examples of qualifying vulnerabilities include:
        1. Unauthenticated Remote Code Execution
        2. Unauthenticated Arbitrary File Upload to Remote Code Execution
        3. Unauthenticated Stored Cross-Site Scripting
        4. Unauthenticated SQL Injection
        5. Missing Authorization to Unauthenticated Data Alteration or Read in a critical way
        6. Authentication Bypass to Admin
        7. Unauthenticated Privilege Escalation
        8. Unauthenticated Arbitrary File Deletion
        9. Unauthenticated Arbitrary File Read
      • Discover and submit 10 or more High Severity, High Impact (i.e. plugin/theme with over 50,000 Active Installations) Vulnerabilities with high quality reports.

        Examples of qualifying vulnerabilities include:
        1. Authenticated (Subscriber/Customer) Remote Code Execution
        2. Authenticated (Subscriber/Customer) Arbitrary File Upload to Remote Code Execution
        3. Authenticated (Subscriber/Customer) Stored Cross-Site Scripting
        4. Authenticated (Subscriber/Customer) SQL Injection
        5. Missing Authorization to Authenticated (Subscriber/Customer) Data Alteration or Read in a critical way
        6. Authenticated (Subscriber/Customer) Privilege Escalation to Admin
        7. Authenticated (Subscriber/Customer) Arbitrary File Deletion
        8. Authenticated (Subscriber/Customer) Arbitrary File Read
    2. In addition to completing at least one of the following:
      • Discover and submit 15 high quality valid Vulnerability reports. These reports have very detailed information and an easy to validate proof of concept.
      • Submit proof of approved offensive security certification or other mastery security certification. The following list is exhaustive, and additional qualifying certifications may be added over time: OSCP, OSWA, OSWE, OSEP, OSED, eWPTx, eWPT, CISSP, CISM, CISA.
    3. Additionally, the researcher must not:
      • have submitted more than 10 false positive or Low Quality Vulnerability reports in a 90 day window.
    4. To maintain 1337 Wordfence Vulnerability Researcher credibility, a Researcher must ensure the following is completed each year:
      • Ensure you don’t submit more than 10 false positive or Low Quality Vulnerability reports in a 90 day window.
      Additionally, at least one of the following must be completed in the same period:
      • Report at least 5 critical severity Vulnerabilities
      • Report at least 10 high severity Vulnerabilities
      • Report at least 20 medium severity Vulnerabilities

    A Researcher’s 1337 Wordfence Vulnerability Researcher status may be revoked at any point if Company suspects the Researcher is abusing the system or at Company’s sole discretion.

  2. Benefits of being a “1337 Wordfence Vulnerability Researcher”

    1. Unlock the ability to submit Vulnerabilities for plugins and themes with lower than the 50k active install count threshold (but higher than 500 active installations).
    2. Pending Vulnerability submission limit will be increased from 10 to 50 pending reports at any given time.
    3. An achievement badge will be added to your profile indicating that you are a “1337 Wordfence Vulnerability Researcher,” which is a Researcher trusted by the Wordfence team for authentic quality Vulnerability research
    4. Earn a 5% Reward Payment bonus on all accepted Vulnerability submissions

4. Additional Researcher Tiers

At any point Defiant may add, remove, or modify researcher tiers, eligibility, benefits, and capabilities at any time. Below we have summarized the current researcher tiers and the benefits that you may earn within each.

Resourceful Researcher Tier

To be eligible for the “Resourceful Researcher” tier, a Researcher must meet and maintain the following requirements.

  1. Eligibility for the Resourceful Researcher Tier
    1. The Researcher must complete at least one of the following:
      • Discover and submit at least one critical severity, high impact, vulnerability in a plugin or theme with >= 50,000 Active Installations. Examples include:
        1. Unauthenticated Remote Code Execution
        2. Unauthenticated Arbitrary File Upload to Remote Code Execution
        3. Unauthenticated Stored Cross-Site Scripting
        4. Unauthenticated SQL Injection
        5. Missing Authorization to Unauthenticated Data Alteration or Read in a critical way
        6. Authentication Bypass to Admin
        7. Unauthenticated Privilege Escalation
        8. Unauthenticated Arbitrary File Deletion
        9. Unauthenticated Arbitrary File Read
      • Discover and submit at least three high severity, high impact, vulnerabilities in plugins or themes with >= 50,000 Active Installations. Examples include:
        1. Authenticated (Subscriber/Customer) Remote Code Execution
        2. Authenticated (Subscriber/Customer) Arbitrary File Upload to Remote Code Execution
        3. Authenticated (Subscriber/Customer) Stored Cross-Site Scripting
        4. Authenticated (Subscriber/Customer) SQL Injection
        5. Missing Authorization to Authenticated (Subscriber/Customer) Data Alteration or Read in a critical way
        6. Authenticated (Subscriber/Customer) Privilege Escalation to Admin
        7. Authenticated (Subscriber/Customer) Arbitrary File Deletion
        8. Authenticated (Subscriber/Customer) Arbitrary File Read
      • Discover and submit at least 10 high/critical severity, medium impact, vulnerabilities in plugins or themes with 1,000 - 50,000 Active Installations. Anything in the above lists in software with 1,000 to 50,000 Active Installs is considered a 'Medium' impact issue and will count towards earning the Resourceful Researcher tier.
    2. In addition to completing the following:
      1. Has not submitted more than 5 False Positive or Low Quality Reports in a 90 day window
  2. Benefits of the “Resourceful Researcher” Tier
    1. Unlock the ability to submit vulnerabilities for bounty rewards in plugins and themes with 10k-50k active installations.
    2. Pending Vulnerability submission limit will be increased from 10 to 25 pending reports at any given time.
    3. An achievement badge will be added to your profile indicating that you are a “Resourceful Researcher,” which is a Researcher that has proven their ability to find vulnerabilities that very positively impact the security of the WordPress ecosystem.

A Researcher’s Tier may be revoked at any point if Company suspects the Researcher is abusing the system or at Company’s sole discretion.

Company reserves the right to grant these tiers at any point, even if the researcher has not met the specified criteria.

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation