The Wordfence Vulnerability Management Portal is designed to provide WordPress plugin and theme vendors with a centralized location to track and manage all vulnerabilities disclosed through the Wordfence Bug Bounty Program, and provide vendors with a portal they can leverage to implement a Vulnerability Disclosure Program to streamline their vulnerability management workflows.
If you’re a software vendor in WordPress, we recommend registering as soon as possible so that you’ll be one step ahead in the event a vulnerability is discovered in your software and you can take full advantage of all the following features.
The Wordfence Vulnerability Management Portal provides a centralized area to track and manage all newly discovered vulnerabilities in software that need remediation and have been reported through the Wordfence Bug Bounty Program, or published as unpatched by other third-party providers.
Each vulnerability submitted through the Wordfence Bug Bounty Program undergoes a validation process.
Only once a vulnerability is validated, you’ll be notified and gain access to a thorough report where you can also track the complete progress from start to finish and upload patches for the Wordfence Threat Intelligence team to review.
All vulnerabilities remediated through the Wordfence Vulnerability Management Portal, those that have already been published, and those published by third parties will all be present in the historical vulnerability view making it possible for you to track the complete history of vulnerabilities in any given software.
Security at Wordfence is a top priority, which is why we provide the ability to delegate access to viewing and managing vulnerability reports for all organizations.
No credential sharing required to maintain optimal security of vulnerability remediation workflows while using the vulnerability management portal.
Flexibility in notifications is incredibly important when it comes to managing vulnerability reports and minimizing noise.
That is why we make it possible to set up to 5 additional contact emails for notifications and allow organizations to configure and tailor exactly what notifications they would like to receive.
Some examples of alerts that are available include:
We understand that not everyone would like to use emails to manage their vulnerability remediation, which is why we have included the ability for vendors to set up custom Slack and/or HTTP webhooks for vulnerability management updates.
This makes it possible for organizations to easily tailor notifications that fit in with their current tools and processes.
There are many reasons you should sign-up to use the Wordfence Vulnerability Management Portal:
The Wordfence Vulnerability Management Portal makes it possible for you to establish your own vulnerability disclosure policy leveraging our portal for central management of new vulnerability reports. By directing vulnerability submissions to Wordfence, you benefit from our free and efficient triage and validation process before the information is relayed to you as the vendor.
You have the flexibility to decide whether to fully leverage Wordfence for your VDP or simply utilize our platform to track and manage vulnerabilities specifically submitted to Wordfence through the Bug Bounty Program.
Here's a simple guide to setting up a VDP using the Wordfence Vulnerability Management Portal:
The first step is to create and publish a policy that acts as a guide for security researchers and helps them understand how
to report vulnerabilities in your software. To do this, add a page to your software's website at a simple URL (we recommend /vulnerability-disclosure-policy)
and include the template provided below. Remember to add your organization's name in the template for each placeholder!
At [ORGANIZATION NAME], security is paramount. We are dedicated to safeguarding our users and their data. We recognize the critical role of independent security researchers in identifying potential vulnerabilities and encourage responsible disclosure in accordance with this policy.
To ensure the efficient triage and resolution of security issues, we have partnered with the Wordfence Bug Bounty Program to manage vulnerability submissions and compensate researchers who contribute to the security of our products.
This policy applies to:
Should you discover a potential vulnerability in one of our products or services, please report it via the Wordfence Bug Bounty Program: https://www.wordfence.com/threat-intel/vulnerabilities/submit
Wordfence will coordinate the triage, validation, and, where applicable, the disbursement of rewards for all vulnerabilities submitted through them, based on their terms and conditions.
We request that you:
In return, we will:
The following are typically outside the scope of our vulnerability disclosure program:
Please refer to the Wordfence Bug Bounty Program Rules for detailed eligibility criteria in regards to bounty rewards: https://www.wordfence.com/threat-intel/bug-bounty-program/#scope
We value the contributions of the security community and appreciate your assistance in enhancing the security of the WordPress ecosystem.
For further information regarding our commitment to security or if you have inquiries, please contact us at \[security@\[vendor\].com\] or reach out via the Wordfence program.
As well as the policy you publish above, you should also create a
security.txt or security.md file
in your WordPress software with the following content. Notice the placeholder under "Policy", you should
insert your own Vulnerability Disclosure Policy URL from the step above here.
# Reporting a Vulnerability ## Contact https://www.wordfence.com/threat-intel/vulnerabilities/submit ## Policy [INSERT YOUR POLICY URL FROM STEP 1] ## Bounty Eligibility https://www.wordfence.com/threat-intel/bug-bounty-program/ ## Acknowledgements https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ We take the security of our software very seriously. If you discover any security vulnerabilities within our project, please report them through Wordfence. To submit a vulnerability report for [Software Name], kindly complete the form available at https://www.wordfence.com/threat-intel/vulnerabilities/submit. Depending on the nature of the vulnerability, you may be eligible for a bounty through the Wordfence Bug Bounty Program. The program's scope eligibility can be reviewed here: https://www.wordfence.com/threat-intel/bug-bounty-program/#scope.
Add the following text to your software's readme.txt file:
###Reporting Security Issues Please report all vulnerabilities found in this software using the Wordfence Vulnerability Submission form at [https://www.wordfence.com/threat-intel/vulnerabilities/submit/]
That's it! Once these steps are completed, researchers will be able to quickly find that any new vulnerabilities discovered in your software should be submitted through the Wordfence Bug Bounty Program. Our team will provide free validation before you receive notification. Additionally, Wordfence will reward researchers with bug bounty rewards for vulnerabilities in-scope of our program.
Currently, the Wordfence Vulnerability Management Portal is invite-only. Please register your interest with this form to request an invitation. We are working towards making the platform more broadly accessible in the future.
There are no special requirements to sign up. Any vendor of a currently active WordPress plugin or theme is eligible to request an invite and sign up. We prioritize vendors who are committed to addressing security vulnerabilities in a timely manner.
Yes, both free and paid WordPress plugins and themes are eligible to register for the Wordfence Vulnerability Management Portal. Our goal is to provide a centralized platform for all WordPress vendors to effectively manage vulnerabilities.
While direct export functionality is not currently available, we understand the value of being able to analyze and manage your vulnerability data offline or integrate it with other systems. We are actively exploring options for future export capabilities and will provide updates as they become available. In the meantime, all vulnerability report details are readily accessible within the portal for review and management.
Timely communication and action on submitted vulnerabilities are crucial for maintaining the security of your software and the WordPress ecosystem. If a submitted vulnerability is validated and we do not receive a response within a reasonable timeframe, we may take the following steps:
We strongly encourage vendors to actively monitor the Vulnerability Management Portal and respond to submissions promptly to ensure the security of their products and maintain a collaborative relationship within the WordPress security community.
Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!
Learn moreWant to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.
The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.
Documentation