Wordfence Bug Bounty Program — Terms and Conditions
These Wordfence Bug Bounty Program (“Program”) Terms and Conditions (“Terms and
Conditions”), describe the terms and conditions of your participation in the Program and are a binding
agreement between you (the “Researcher”) and Defiant, Inc., a Delaware corporation, and its
officers, directors, employees, agents, licensees, independent contractors, successors, and assigns are
referred to herein collectively as “Company.”
For the purposes of these Terms and Conditions, a “Vulnerability” is any information
submitted through the Wordfence Vulnerability Submission Form.
Researchers ("you", "your") may submit Vulnerabilities of any type for CVE assignment via the Wordfence Vulnerability
Submission Form located at https://www.wordfence.com/threat-intel/vulnerabilities/submit, or our CVE request form located at
https://www.wordfence.com/request-cve/. Independent Researchers do not need to
participate in the Program in order to report Vulnerabilities to Company or request a CVE ID. If you would like
to report a Vulnerability to Company for CVE assignment, or addition to the Wordfence Intelligence
Vulnerability database, please use the Wordfence Vulnerability Submission Form.
To participate in the Program, Researchers must accept and follow these Terms and Conditions. Company
reserves the right to modify the scope, rules, and vulnerability reward payouts at any time. Company also
reserves the right to suspend or terminate the Program, in whole or in part, at any time, for any reason, with
or without notice to Researchers. These Terms and
Conditions are incorporated into and made part of the Wordfence Terms of Service by reference. If you do not
agree to these Terms and Conditions, do not submit Vulnerabilities through the Program.
1. Wordfence Bug Bounty Program Rules
The Researcher agrees as follows:
-
Researcher Accounts and General Rules
- To participate in the Program, Researchers must create a Researcher Account and be
authenticated at the time the Researcher submits the Vulnerability. To create a Researcher
Account, please visit: https://www.wordfence.com/threat-intel/researcher-register.
- When you submit a Vulnerability, the Researcher Profile information you provide in connection
with your Researcher Account, including your name, alias, display name, X (formerly Twitter) handle,
Facebook url, LinkedIn url, website address, and biographical information may be displayed
publicly and shared with Company service providers and other Researchers.
- Company must be the only organization a Researcher submits the Vulnerability to, and the
Vulnerability must not be previously disclosed elsewhere, in order to be eligible for Reward
Payment as set forth in the Wordfence Bug Bounty Reward Payment Schedule.
-
You will not publicly disclose any of the Vulnerability’s details until (a) Company has
completed the Responsible Disclosure process set forth at
https://www.wordfence.com/blog/2021/07/youve-found-a-vulnerability-now-what-a-guide-to-responsible-disclosure/
and (b) the CVE has been made public. Company will contact you when these two activities are
complete.
- Vulnerabilities will be considered confidential until they have been published in the
Wordfence Intelligence vulnerability database.
- If you share details of the Vulnerability with a third party while the company is
conducting the responsible disclosure process, you will be given a warning for the first
offense. Additional offenses may result in you being banned from participating in the
program.
-
Eligibility and Reward Payment
- For any submitted Vulnerability to be eligible for Reward Payment, the Vulnerability must be
within the bug bounty program scope outlined in the section titled “Bug Bounty Program Scope”
below, and the Vulnerability must be Validated as set forth in Section 2(b) of the
Wordfence Bug Bounty Program Submission Release.
- Any Vulnerability may be rejected or returned to the Researcher if it is missing complete
details that help validate and confirm the existence of the Vulnerability.
- A researcher will be considered a New Researcher upon registering an account for participating
in the Bug Bounty Program. New Researchers are considered those who have submitted fewer than
10 validated submissions, and are not in the Resourceful Researcher or 1337 Researcher tier.
New Researchers can only have a total of 15 pending Vulnerability Reports submitted at any
given time, with up to 10 of those being considered in-scope for a bounty reward. Once a New
Researcher has submitted the limit of 15 pending Vulnerability Submissions, they will no longer
be able to submit any new Vulnerability Reports until a pending report has been triaged.
- A Standard Researcher can only have 10 pending Vulnerability submissions open at any given time, unless
they are a Researcher in one of our additional
researcher tiers. 1337 Wordfence Vulnerability Researchers can have 50 pending Vulnerability
submissions open at any given time, and Resourceful Researchers can have 25 pending
Vulnerability submissions open at any given time.
- Vulnerabilities dependent upon one or more additional vulnerabilities to exploit are not
eligible for Reward Payment, unless the vulnerable software and/or the current version of
WordPress Core include(s) all vulnerabilities required to perform a successful exploit.
-
Vulnerabilities that require more than one CVE assignment may not be eligible
for more than one Reward Payment (as set forth and defined in the
Wordfence Bug Bounty Program Submission Release). The Reward
Payment will be awarded for the higher paying CVE’s vulnerability type.
- Example: Missing Authorization vulnerabilities that are also vulnerable to Cross-Site
Request Forgery are only eligible for the missing authorization Reward Payment,
however, the report may receive two CVEs depending on how the two issues were
patched.
- A Vulnerability that affects multiple plugins, themes, libraries, or other software components
with the same vulnerable code will be awarded a Reward Payment for the base rate along with a
multiplier depending on how many components are affected, as set forth in the
Wordfence Bug Bounty Reward Payment Schedule.
- Vulnerabilities that require high-level privileges to exploit (PR:H), such as access to a user
account with the administrator or editor role, may receive a CVE ID, but are not eligible for a
Reward Payment.
- At Company’s sole discretion, Vulnerability submissions may be eligible for bonuses to award
exceptional work.
- In the event of two or more Researchers submitting the same Vulnerability in the same
component, the Researcher who submitted first will be the one eligible to receive Reward
Payment.
- Vulnerabilities that have the same code-base as a previously disclosed Vulnerability that
received Reward Payment will not be awarded any additional Reward Payment.
- Only one critical impact bounty will be awarded to the first submitting researcher for any given vulnerability
type and impact reported and present in the most current version of the affected software,
regardless of any additional pieces of functionality being affected and submitted by additional
researchers. For example, if researcher A submits a Contributor-level Stored Cross-Site
Scripting vulnerability in plugin “ABC” and then three other researchers submit
Contributor-level Stored Cross-Site Scripting vulnerabilities in plugin “ABC” in three different
widgets, only researcher A will be granted a critical impact bounty award. The subsequent researchers
may be awarded a lower impact bounty at Defiant's discretion. However, if one of the other
researchers submits a different type of Stored Cross-Site Scripting, such as Subscriber-level
Stored Cross-Site Scripting, they would be eligible for a critical impact bounty.
- Bypasses to patches in vulnerabilities originally reported through the bug bounty program are
not eligible for a full bounty reward within 10 version releases, but may be eligible for a
reduced bounty on a case-by-case basis unless we suspect there was gaming involved.
- Once a PHP Object Injection gadget has been discovered and reported in a plugin/theme, only the
first PHP Object Injection vulnerability reported leveraging that gadget will be eligible for a
bounty at the full rate of impact (i.e. RCE). Any subsequent PHP Object Injection
vulnerabilities leveraging the same gadget, and submitted within 30 versions of the last
reported PHP Object Injection, will be awarded at the PHP Object Injection w/out Gadget rate
unless a new gadget is discovered and demonstrated.
- A vulnerability being assigned a CVE ID is not a guarantee that the vulnerability will be
in-scope for a reward payment.
-
Wordfence Refer-A-Researcher Program
- Some Researchers may be eligible to participate in the Wordfence Refer-A-Researcher Program to
earn bonuses for referring Researchers. The following terms and conditions apply to the
Wordfence Refer-A-Researcher Program:
-
Eligibility Criteria and Application
- Researchers must be registered and approved with the Wordfence Bug Bounty Program for a
minimum of one month.
- Researchers must have submitted at least ten validated in-scope vulnerabilities.
- Company reserves the right to approve or deny any application to participate in the
Wordfence Refer-A-Researcher Program at its discretion.
- Any Researcher found violating the terms will be banned from the Wordfence
Refer-A-Researcher Program.
- Both the Referring and Referred Researchers may face bans or temporary restrictions from
the Bug Bounty Program at the discretion of Company.
-
Referral Process
- Upon approval, Researchers (“Referring Researchers”)
will receive a referral link to share with potential researchers
(“Referred Researchers”).
- Referred Researchers must register using the Referring Researcher’s referral link for
the Referring Researcher to earn a bonus.
-
Bonus Structure and Payment
- If a Referred Researcher submits five Vulnerabilities that are accepted within their
first year of the Referred Researcher’s registration, the Referring Researcher is
eligible to receive a bonus of 20% of the total value of the first five Reward Payments
that the Referred Researcher earned.
- Bonuses will be paid in a single installment once all five Vulnerabilities are accepted
and according to the Wordfence Bug Bounty Reward Payment Schedule.
-
Prohibited Acts, Banning, and Restriction
- If we suspect an individual is using automated tools to perform bulk vulnerability discovery,
we reserve the right to restrict the level of Reward Payments that individual is eligible
for.
- Developers may not report Vulnerabilities in their own software.
- Company may terminate, ban, or restrict a Researcher for any reason at the sole discretion of
Company.
- If a Researcher creates a second account in an attempt to bypass any of these rules or
restrictions, both accounts may be permanently banned.
- Researchers violating any of these Terms and Conditions may be restricted or banned from the
Program and be unable to submit Vulnerabilities.
-
If a Researcher submits more than 2 low-quality AI Hallucinated reports (for example, a
vulnerability report that describes a vulnerability that does not exist in the codebase, follows
typical AI-generated structure, or includes a proof of concept that has not been tested and does
not function as described) over a period of 30 days, the Researcher’s ability to submit
Vulnerabilities will be restricted, at the Company’s discretion, for the next 30 days.
- After the initial 2 AI Hallucinated reports, if another 2 AI Hallucinated reports are
submitted, then the Researcher may be permanently banned from participating in the
Program.
-
If a Researcher submits more than 5 false positive, low-quality (for example, simply outputting
the results of a security scanner), or out-of-scope Vulnerabilities over a period of 7 days,
the Researcher’s ability to submit Vulnerabilities will be restricted, at Company’s discretion,
for the next 7 days.
- After the first 5 false positive reports, if a Researcher submits more than 5
false positive, low-quality (for example, simply outputting the results of a security
scanner), or out-of-scope Vulnerabilities over a subsequent period of 7 days, the
Researcher’s ability to submit Vulnerabilities will be restricted, at Company’s
discretion, for the next 14 days.
- After the first 10 false positive reports, if a Researcher submits more than 10
false positive, low-quality (for example, simply outputting the results of a security
scanner), or out-of-scope Vulnerabilities over a subsequent period of 14 days, the
Researcher’s ability to submit Vulnerabilities will be restricted, at Company’s
discretion, for the next 30 days.
- After 30 false positive, low-quality, or out-of-scope Vulnerability submissions, the
Researcher may be permanently banned from participating in the Program.
- If we suspect a researcher is attempting to game the Bug Bounty Program to bypass current rules
and bounty reward criteria, we may restrict or ban the researcher from being able to
participate in the program. Examples of gaming include a) withholding vulnerability information
from a Vulnerability Submission in attempt to earn an additional bounty by submitting additional
information (i.e. a bypass) in a subsequent new report when the initial reported vulnerability
is suspected to be patched b) working as a team to submit multiple affected components of the
same vulnerability type in a single plugin through different reports to earn a bounty for each
affected component (i.e. widget).
- If a New Researcher submits 10 out of scope reports in a period of 7 days, they will be
throttled and no longer able to submit any more reports for a period of 7 days.
- If artificial intelligence (AI) tools are used at any stage to generate or assist with a
vulnerability report, this must be accurately disclosed in the vulnerability submission form.
Misrepresenting or failing to disclose the use of AI tools may result in the submission being
deemed ineligible for a reward and may lead to a permanent ban from the Program.
- Researchers are expected to classify the severity and category of their submissions correctly.
A pattern of misclassifying vulnerabilities in an attempt to obtain priority triage or
preferential queue placement may result in suspension or permanent removal from the Program.
- Vulnerability reports generated using AI must be manually verified by the submitting Researcher
prior to submission. Submitting AI-generated, or other, reports without proper manual validation
may result in the Researcher being restricted or permanently banned from the Program.
- The automated use of AI or other tools to generate and submit vulnerability reports in bulk is
strictly prohibited. Accounts found engaging in automated or large-scale AI-generated
submissions may be suspended or permanently banned from the Program.
-
Referring and Referred Researchers are prohibited from:
- Creating multiple accounts to submit vulnerabilities and earn bonuses; or
- Soliciting others to create accounts and submit vulnerabilities on their behalf.
2. Bug Bounty Program Scope
-
Assets Considered In Scope
-
High Threat Vulnerabilities
All WordPress plugins and themes that can be run locally, both free and premium, with >= 25
active installations are in scope for all researchers for a select list of high threat
vulnerabilities when exploitable by unauthenticated or low-level authenticated (Subscriber) attackers.
These vulnerabilities are exclusively listed here:
- Arbitrary PHP File Upload
- Arbitrary PHP File Read
- Arbitrary PHP File Deletion
- Arbitrary Options Update
- Remote Code Execution
- Authentication Bypass to Admin
- Privilege Escalation to Admin
Note: High Threat Vulnerabilities in plugins and themes with between 25 and 999 Active Installations must be listed in the WordPress.org Plugin Repository to be in-scope.
-
Common and Dangerous Vulnerabilities
All WordPress plugins and themes that can be run locally, both free and premium, with >= 500
active installations are in scope for all researchers for a select list of common and dangerous
vulnerabilities when exploitable by unauthenticated or low-level authenticated (Subscriber)
attackers. These vulnerabilities are exclusively listed here:
- Stored Cross-Site Scripting
- SQL Injection
Note: Common and Dangerous Vulnerabilities in plugins and themes with between 500 and 999
Active Installations must be listed in the WordPress.org Plugin Repository to be in-scope.
-
All Remaining In-Scope Vulnerabilities
All WordPress plugins and themes that can be run locally, both free and premium, with
>=50,000 active installations are in scope for all Researchers, with a few exceptions detailed
in the out-of-scope section. If you are a “1337 Wordfence Vulnerability Researcher”
(defined below) all WordPress plugins and themes that can be run locally, both free and premium,
with >=500 active installations are in scope, with a few exceptions detailed in the
out-of-scope section. If you are in our “Resourceful Researcher” researcher tier (defined
below) all WordPress plugins and themes that can be run locally, both free and premium, with
>=10,000 active installations are in scope, with a few exceptions detailed in the out-of-scope
section.
-
Assets Considered Out of Scope
- WordPress Core is considered out of scope for the Program, however, we may still assign a CVE
ID to any Vulnerability discovered in core.
-
Software, services, and developers that maintain a publicly published bug bounty or responsible
disclosure program, managed directly by the developer, are considered out-of-scope for the
Program (“Out-Of-Scope Assets”). A list of Out-Of-Scope Assets is set forth below and may be
updated by Defiant from time-to-time (the “Out-Of-Scope Asset List”). Whereas Defiant monitors
software, services, and developers to determine if they maintain their own bug bounty or
responsible disclosure program, new programs are continually released and we cannot guarantee
that we have identified and included all such programs in the Out-Of-Scope Asset List. Defiant
will not pay Reward Payments for Vulnerabilities you report if the Vulnerability relates to an
Out-Of-Scope Asset, regardless of whether the Out-Of-Scope Asset is included on the
Out-Of-Scope Asset List. If you are unsure if you can report a Vulnerability to us, and
potentially earn a Reward Payment, please
contact us at wfi-support@wordfence.com.
For avoidance of doubt, any software listed under a competing WordPress Vulnerability Disclosure
Program (VDP), Bug Bounty Program, or vulnerability database is not considered out-of-scope to
the extent that the Vulnerability is reported directly to us and not a competitor.
Out-Of-Scope Asset List:
-
WordPress Core
-
All Automattic Products
-
All Facebook Products
-
All Google Products
-
All Siteground Products
-
All Yoast Products
- Plugins or Themes that are closed to downloads or sales are not in scope, unless the closure
reason was due to a Vulnerability the reporting Researcher found and responsibly disclosed, and
the Researcher has adequate proof they were the one who found and reported the issue.
- Any web service, application, or endpoint associated with a WordPress plugin or theme that is
not run locally (such as an API running on a plugin vendor’s website) is considered out of
scope. For the avoidance of doubt, this includes any vulnerability that is exploitable via a
WordPress plugin or theme, but can be patched on an external server or service, and is not
within the WordPress plugin or theme itself.
- WordPress plugins or themes not downloadable from WordPress.org with fewer than 1,000 estimated
active installations or sales.
-
Vulnerabilities Considered In-Scope
All issues in WordPress Plugins and Themes with a considerable impact to the confidentiality, integrity, and availability of a WordPress site are considered in scope of this program as long as they do not require high level permissions, such as administrator or editor (i.e. CVSSv3.1 PR:H) to exploit. The following is a list of some common vulnerabilities that will be accepted.
- Stored Cross-Site Scripting
- Reflected Cross-Site Scripting
- Cross-Site Request Forgery, that has a considerable impact on a site's security
- Missing Authorization, that leads to a considerable impact on a site's security
- Arbitrary Content Deletion
- SQL Injection
- Insecure Direct Object Reference
- Arbitrary File Upload
- Arbitrary File Download/Read
- Arbitrary File Deletion
- Local File Include/Remote File Include
- Directory Traversal
- Privilege Escalation to Admin
- Privilege Escalation to Non-Admin
- Authentication Bypass to Admin
- Authentication Bypass to Non-Admin
- Remote Code Execution/Code Injection
- Information Disclosure
- PHP Object Injection
- Intentional Backdoors Added by Developers that are Accessible by Threat Actors
-
Vulnerabilities Considered Out of Scope
Vulnerabilities that have a minimal impact on the security of WordPress sites, or are unlikely to be successfully exploited in the wild will likely be considered out of scope for the program and will be rejected for CVE assignment upon submission.
- Anything listed in our 'Common False Positive Reports' is automatically considered Out of Scope as they are not considered valid vulnerabilities
- Business Logic Flaws where the demonstrated impact is primarily business-related rather than security-related. This includes, but is not limited to, issues such as payment bypasses, pricing manipulation, discount or coupon abuse, order workflow abuse, or other logic flaws that affect revenue, transactions, or business operations without introducing a direct security impact.
- All DoS Vulnerabilities
- Software containing vulnerable packages or dependencies that are not verifiably exploitable in that plugin or theme
- Any Vulnerability requiring PR:H to Exploit. Administrator, Editor, and Shop Manager roles, along with any other role that has the
unfiltered_html capability fall into this category.
- Any Vulnerability requiring mid-level authentication to exploit. This includes Contributor and Author roles, along with any other role that needs to be granted by an administrator (i.e. not a common default registration role).
- Open Redirect
- Server-Side Request Forgery
- Vulnerabilities dependent on successfully exploiting a race condition that is not easily replicable in a common configuration
- Cache Poisoning, where this is not a considerable and demonstrable impact to site's security
- Server-Side Request Forgery via DNS Rebinding (i.e. if
wp_safe_remote_* or wp_http_validate_url() is in use, we do not consider the issue a valid SSRF vulnerability)
- API Key Updates/Overwrites/Reads
- Vulnerabilities that can only be exploited by an administrator explicitly granting access to a lower-privileged user where the likelihood of an administrator granting access is minimal or the administrator is granting access to functionality and features that can be abused
- Vulnerabilities that require excessive brute force to exploit. Please note we may accept vulnerabilities as in scope where brute force is required and the likelihood of success is relatively high. Scope eligibility will be determined on a case-by-case basis.
- Private/Hidden/Draft/Pending/Password Protected Post Access
The list of 'Common False Positive Reports' is as follows:
The following issues are frequently reported to our program but are not considered valid vulnerabilities and are routinely rejected. This list is not exhaustive and there may be other issues that we reject, these are just some of the most common issues we reject. Please do not submit reports for the following:
- Low-Impact or Theoretical Issues
- Theoretical vulnerabilities
- Issues that lead to username enumeration
- Lack of HTTP security headers
- Clickjacking
- Full path disclosure
- Coupon code exposure
- Wishlist updates
- Google Maps API key access
- Endpoints without brute-force or rate limiting protections (rate limiting is considered a server-side control)
- Any vulnerability with a CVSS 3.1 score lower than 4.0 that cannot be leveraged to achieve a higher impact
- Injection & Client-Side Issues (Non-Exploitable/Low Impact)
- CSV Injection
- CSS Injection
- HTML Injection
- Self Cross-Site Scripting (i.e. the payload is not stored and only rendered upon the initial action)
- Reflected Cross-Site Scripting via headers
- Cross-Site Scripting via SVG file uploads
- File uploads containing embedded client-side scripts or macros (e.g., XSS in PDFs)
- Malicious content stored in safe file types (e.g., PHP code inside a
.jpg file)
- Double extension file upload attacks (e.g.,
.php.png)
- Safe filetype uploads (e.g.,
.jpg, .png) where upload functionality is intentional
- Authentication, Authorization & Access Control (Expected or Intentional Behavior)
- IP Spoofing
- CAPTCHA bypasses
- CORS issues
- Tabnabbing
- TOCTOU
- Dismissing notices via CSRF or missing authorization
- Cross-Site Request Forgery:
- On unauthenticated forms with no sensitive actions
- On read-only actions
- Missing authorization where:
- A valid nonce protects the action
- The nonce is not exposed to lower-privileged users
- Access keys or tokens used for authorization when adequately secure
- Arbitrary shortcode execution by Contributor-level users or higher
- High-level (Administrator, Editor, Shop Manager) XSS requiring
unfiltered_html
- Intentional functionality restricted to administrators (e.g., PHP snippet plugins, tracking script insertion)
- Intentional functionality where scope is appropriately limited (i.e. user can submit a post with a featured image due to the plugin enabling such functionality as a well documented feature)
- User registration bypass where registration is intentionally enabled through the software functionality or does not lead to privilege escalation
- Unlimited voting, liking, or counting issues (i.e. a page counter where the count can be increased by several requests)
- 2 Factor Authentication Bypasses
- Missing authorization without a consequential confidentiality, integrity, or availability impact.
- Environmental/Configuration-Based Issues
- Vulnerabilities only exploitable on EOL software (PHP, MySQL, Apache, Nginx, OpenSSL, etc.)
- Any SQL injection requiring
wp_magic_quotes to be disabled
- Vulnerabilities requiring local server access
- Vulnerabilities requiring unsafe PHP configuration changes (e.g., enabling
allow_url_fopen)
- Secrets stored in plaintext that cannot be exploited through another vulnerability
- Uploaded files in publicly accessible directories where exposure does not lead to site compromise
- Software containing vulnerable dependencies that are not verifiably exploitable within the plugin or theme
- Information exposed when
WP_DEBUG is enabled.
- Vulnerabilities dependent on an administrator misconfiguring or insecurely configuring their settings or environment.
- Browser Version Requirements
- Vulnerabilities that only affect users of outdated or unpatched browsers (defined as two stable versions behind the latest release.)
3. 1337 Wordfence Vulnerability Researcher Program
The 1337 Wordfence Vulnerability Researcher Program is a program designed to incentivize the most
high-quality Researchers contributing to the security of the WordPress ecosystem. Once a Researcher
has demonstrated authenticity and meaningful research, by meeting the outlined criteria, they will be
awarded the “1337 Wordfence Vulnerability Researcher” status that will add a flag to their Researcher
profile and unlock additional capabilities as a WordPress security Researcher, such as the ability to
earn Reward Payments for lower install count software and a bonus on all reported Vulnerabilities.
-
Eligibility for the 1337 Wordfence Vulnerability Researcher Program
To be considered for “1337 Wordfence Vulnerability Researcher” status, a Researcher must meet and
maintain the following requirements.
-
The Researcher must complete at least one of the following:
- Discover and submit 5 or more Critical Severity, High Impact (i.e. plugin/theme with
over 50,000 Active Installations) Vulnerabilities with high quality reports.
Examples of qualifying vulnerabilities include:
- Unauthenticated Remote Code Execution
- Unauthenticated Arbitrary File Upload to Remote Code Execution
- Unauthenticated Stored Cross-Site Scripting
- Unauthenticated SQL Injection
- Missing Authorization to Unauthenticated Data Alteration or Read in a
critical way
- Authentication Bypass to Admin
- Unauthenticated Privilege Escalation
- Unauthenticated Arbitrary File Deletion
- Unauthenticated Arbitrary File Read
- Discover and submit 10 or more High Severity, High Impact (i.e. plugin/theme with
over 50,000 Active Installations) Vulnerabilities with high quality reports.
Examples of qualifying vulnerabilities include:
- Authenticated (Subscriber/Customer) Remote Code Execution
- Authenticated (Subscriber/Customer) Arbitrary File Upload to Remote
Code Execution
- Authenticated (Subscriber/Customer) Stored Cross-Site Scripting
- Authenticated (Subscriber/Customer) SQL Injection
- Missing Authorization to Authenticated (Subscriber/Customer) Data Alteration
or Read in a critical way
- Authenticated (Subscriber/Customer) Privilege Escalation to Admin
- Authenticated (Subscriber/Customer) Arbitrary File Deletion
- Authenticated (Subscriber/Customer) Arbitrary File Read
-
In addition to completing at least one of the following:
- Discover and submit 15 high quality valid Vulnerability reports. These reports have very
detailed information and an easy to validate proof of concept.
- Submit proof of approved offensive security certification or other mastery security
certification. The following list is exhaustive, and additional qualifying
certifications may be added over time: OSCP, OSWA, OSWE, OSEP, OSED, eWPTx, eWPT,
CISSP, CISM, CISA.
-
Additionally, the researcher must not:
- have submitted more than 10 false positive or Low Quality Vulnerability reports in a 90 day window.
-
To maintain 1337 Wordfence Vulnerability Researcher credibility, a Researcher must ensure the
following is completed each year:
- Ensure you don’t submit more than 10 false positive or Low Quality Vulnerability
reports in a 90 day window.
Additionally, at least one of the following must be completed in the same period:
- Report at least 5 critical severity Vulnerabilities
- Report at least 10 high severity Vulnerabilities
- Report at least 20 medium severity Vulnerabilities
A Researcher’s 1337 Wordfence Vulnerability Researcher status may be revoked at any point if Company
suspects the Researcher is abusing the system or at Company’s sole discretion.
-
Benefits of being a “1337 Wordfence Vulnerability Researcher”
- Unlock the ability to submit Vulnerabilities for plugins and themes with lower than the 50k
active install count threshold (but higher than 500 active installations).
- Pending Vulnerability submission limit will be increased from 10 to 50 pending reports at any
given time.
- An achievement badge will be added to your profile indicating that you are a “1337 Wordfence
Vulnerability Researcher,” which is a Researcher trusted by the Wordfence team for authentic
quality Vulnerability research
- Earn a 5% Reward Payment bonus on all accepted Vulnerability submissions
4. Additional Researcher Tiers
At any point Defiant may add, remove, or modify researcher tiers, eligibility, benefits, and capabilities at any time.
Below we have summarized the current researcher tiers and the benefits that you may earn within each.
Resourceful Researcher Tier
To be eligible for the “Resourceful Researcher” tier, a Researcher must meet and maintain the following requirements.
-
Eligibility for the Resourceful Researcher Tier
-
The Researcher must complete at least one of the following:
-
Discover and submit at least one critical severity, high impact, vulnerability in a plugin or theme
with >= 50,000 Active Installations. Examples include:
- Unauthenticated Remote Code Execution
- Unauthenticated Arbitrary File Upload to Remote Code Execution
- Unauthenticated Stored Cross-Site Scripting
- Unauthenticated SQL Injection
- Missing Authorization to Unauthenticated Data Alteration or Read in a
critical way
- Authentication Bypass to Admin
- Unauthenticated Privilege Escalation
- Unauthenticated Arbitrary File Deletion
- Unauthenticated Arbitrary File Read
-
Discover and submit at least three high severity, high impact, vulnerabilities in plugins or themes
with >= 50,000 Active Installations. Examples include:
- Authenticated (Subscriber/Customer) Remote Code Execution
- Authenticated (Subscriber/Customer) Arbitrary File Upload to Remote
Code Execution
- Authenticated (Subscriber/Customer) Stored Cross-Site Scripting
- Authenticated (Subscriber/Customer) SQL Injection
- Missing Authorization to Authenticated (Subscriber/Customer) Data Alteration or
Read in a critical way
- Authenticated (Subscriber/Customer) Privilege Escalation to Admin
- Authenticated (Subscriber/Customer) Arbitrary File Deletion
- Authenticated (Subscriber/Customer) Arbitrary File Read
-
Discover and submit at least 10 high/critical severity, medium impact, vulnerabilities in plugins or
themes with 1,000 - 50,000 Active Installations. Anything in the above lists in software
with 1,000 to 50,000 Active Installs is considered a 'Medium' impact issue and will
count towards earning the Resourceful Researcher tier.
-
In addition to completing the following:
- Has not submitted more than 5 False Positive or Low Quality Reports in a 90 day window
-
Benefits of the “Resourceful Researcher” Tier
- Unlock the ability to submit vulnerabilities for bounty rewards in plugins and themes with
10k-50k active installations.
- Pending Vulnerability submission limit will be increased from 10 to 25 pending reports at
any given time.
- An achievement badge will be added to your profile indicating that you are a “Resourceful Researcher,”
which is a Researcher that has proven their ability to find vulnerabilities that very
positively impact the security of the WordPress ecosystem.
A Researcher’s Tier may be revoked at any point if Company suspects the Researcher is abusing the system or
at Company’s sole discretion.
Company reserves the right to grant these tiers at any point, even if the researcher has not met the
specified criteria.