Wordfence Vulnerability Management Portal
for WordPress Software Vendors

Protect your users. Strengthen your brand. Lead with responsible security.

The Wordfence Vulnerability Management Portal is designed to provide WordPress plugin and theme vendors with a centralized location to track and manage all vulnerabilities disclosed through the Wordfence Bug Bounty Program, and provide vendors with a portal they can leverage to implement a Vulnerability Disclosure Program to streamline their vulnerability management workflows.

If you’re a software vendor in WordPress, we recommend registering as soon as possible so that you’ll be one step ahead in the event a vulnerability is discovered in your software and you can take full advantage of all the following features.

Key Features and Highlights

Active Vulnerability Tracking

The Wordfence Vulnerability Management Portal provides a centralized area to track and manage all newly discovered vulnerabilities in software that need remediation and have been reported through the Wordfence Bug Bounty Program, or published as unpatched by other third-party providers.

Screenshot of Active Vulnerability Tracking

Detailed Vulnerability Reports

Each vulnerability submitted through the Wordfence Bug Bounty Program undergoes a validation process.

Only once a vulnerability is validated, you’ll be notified and gain access to a thorough report where you can also track the complete progress from start to finish and upload patches for the Wordfence Threat Intelligence team to review.

Screenshot of Detailed Vulnerability Reports

Historical Vulnerability Tracking

All vulnerabilities remediated through the Wordfence Vulnerability Management Portal, those that have already been published, and those published by third parties will all be present in the historical vulnerability view making it possible for you to track the complete history of vulnerabilities in any given software.

Screenshot of Historical Vulnerability Tracking

Delegated Team Member Access

Security at Wordfence is a top priority, which is why we provide the ability to delegate access to viewing and managing vulnerability reports for all organizations.

No credential sharing required to maintain optimal security of vulnerability remediation workflows while using the vulnerability management portal.

Screenshot of Delegated Team Member Access

Customizable Alerts

Flexibility in notifications is incredibly important when it comes to managing vulnerability reports and minimizing noise.

That is why we make it possible to set up to 5 additional contact emails for notifications and allow organizations to configure and tailor exactly what notifications they would like to receive.

Some examples of alerts that are available include:

  • New Vulnerability Reported
  • Patch Approved
  • Patch Requires Changes
  • Vulnerability Published
  • Vulnerability Rejected in Triage
  • Response Received from Wordfence
Screenshot of Customizable Alerts

HTTP/Slack Webhook Integration

We understand that not everyone would like to use emails to manage their vulnerability remediation, which is why we have included the ability for vendors to set up custom Slack and/or HTTP webhooks for vulnerability management updates.

This makes it possible for organizations to easily tailor notifications that fit in with their current tools and processes.

Screenshot of HTTP/Slack Webhook Integration

There are many reasons you should sign-up to use the Wordfence Vulnerability Management Portal:

Streamlined Vulnerability Management & Notifications

The Wordfence Vulnerability Management Portal enables comprehensive tracking of vulnerabilities reported through Wordfence, or those publicly identified as unpatched, all within a centralized platform. This facilitates the refinement and streamlining of the vulnerability management process.

Furthermore, integration of workflow notifications at each stage is achievable through the utilization of webhooks or customization of notification preferences.

Streamlined Bug Bounty Submissions and Rewards for Researchers

The Wordfence Vulnerability Management Portal serves as a central hub where security researchers can easily report vulnerabilities they discover in WordPress plugins and themes. This streamlined process encourages more vulnerability disclosures, ultimately contributing to a more secure WordPress ecosystem and more research in your products.

Furthermore, researchers who submit valid vulnerabilities through the Wordfence Bug Bounty Program are eligible to earn rewards, incentivizing their valuable contributions to the platform and the security of WordPress software.

Be Informed About Unpatched Vulnerability Disclosures From Third Parties

Stay ahead of potential security risks with timely notifications whenever third parties disclose unpatched vulnerabilities in your software.

The Wordfence Vulnerability Management Portal keeps you informed, allowing you to take proactive steps to address these issues before they can be exploited or your customers get alarmed.

Streamlined Pre-Release Patch Reviews

The Wordfence Vulnerability Management Portal facilitates the secure and efficient review of pre-release patches. Vendors can upload patches for vulnerabilities, allowing the Wordfence Threat Intelligence team to analyze and validate the fixes before they are publicly released.

This process helps ensure the effectiveness and security of the patches, reducing the risk of further vulnerabilities or unintended consequences.

A Portal to Manage A Vulnerability Disclosure Program

The Wordfence Vulnerability Management Portal provides a platform for vendors to set up a vulnerability disclosure program for free.

By optionally setting up a vulnerability disclosure program leveraging the Wordfence Vulnerability Management platform, vendors can take advantage of Wordfence's free triage and validation of security submissions before receiving the information.

This streamlines the initial assessment process, saving vendors valuable time and resources in managing and responding to potential vulnerabilities.

No Vendor Lock-In

The Wordfence Vulnerability Management Portal offers flexibility, allowing for independent management of your vulnerability disclosure program.

You can utilize the program solely to integrate disclosures from Wordfence into your existing workflows and management procedures, without necessitating reliance on external vendor services.

The Wordfence Vulnerability Management Portal makes it possible for you to establish your own vulnerability disclosure policy leveraging our portal for central management of new vulnerability reports. By directing vulnerability submissions to Wordfence, you benefit from our free and efficient triage and validation process before the information is relayed to you as the vendor.

You have the flexibility to decide whether to fully leverage Wordfence for your VDP or simply utilize our platform to track and manage vulnerabilities specifically submitted to Wordfence through the Bug Bounty Program.

Here's a simple guide to setting up a VDP using the Wordfence Vulnerability Management Portal:

Step 1: Publish a Vulnerability Disclosure Policy

The first step is to create and publish a policy that acts as a guide for security researchers and helps them understand how to report vulnerabilities in your software. To do this, add a page to your software's website at a simple URL (we recommend /vulnerability-disclosure-policy) and include the template provided below. Remember to add your organization's name in the template for each placeholder!

Vulnerability Disclosure Policy

At [ORGANIZATION NAME], security is paramount. We are dedicated to safeguarding our users and their data. We recognize the critical role of independent security researchers in identifying potential vulnerabilities and encourage responsible disclosure in accordance with this policy.

To ensure the efficient triage and resolution of security issues, we have partnered with the Wordfence Bug Bounty Program to manage vulnerability submissions and compensate researchers who contribute to the security of our products.

Scope

This policy applies to:

  • All WordPress plugins and themes owned or maintained by [ORGANIZATION NAME].

Reporting a Vulnerability

Should you discover a potential vulnerability in one of our products or services, please report it via the Wordfence Bug Bounty Program: https://www.wordfence.com/threat-intel/vulnerabilities/submit

Submission via Wordfence Bug Bounty Program

Wordfence will coordinate the triage, validation, and, where applicable, the disbursement of rewards for all vulnerabilities submitted through them, based on their terms and conditions.

Guidelines for Responsible Disclosure

We request that you:

  • Refrain from violating privacy, destroying data, or disrupting service.
  • Allow us a reasonable period to investigate and resolve any issues before public disclosure. Wordfence will follow their responsible disclosure policy as outlined here: https://www.wordfence.com/security/

In return, we will:

  • Acknowledge your submission promptly through Wordfence.
  • Act expeditiously to resolve verified vulnerabilities.
  • Provide public credit (if desired) upon resolution of the issue.

Out of Scope

The following are typically outside the scope of our vulnerability disclosure program:

  • Social engineering attacks.
  • Denial of Service (DoS) or brute-force attacks.
  • Issues requiring physical access.
  • Vulnerabilities in third-party services not under [ORGANIZATION NAME] control.

Please refer to the Wordfence Bug Bounty Program Rules for detailed eligibility criteria in regards to bounty rewards: https://www.wordfence.com/threat-intel/bug-bounty-program/#scope

Thank You

We value the contributions of the security community and appreciate your assistance in enhancing the security of the WordPress ecosystem.

For further information regarding our commitment to security or if you have inquiries, please contact us at \[security@\[vendor\].com\] or reach out via the Wordfence program.

Step 2: Include a security.txt file with your software

As well as the policy you publish above, you should also create a security.txt or security.md file in your WordPress software with the following content. Notice the placeholder under "Policy", you should insert your own Vulnerability Disclosure Policy URL from the step above here.

# Reporting a Vulnerability
## Contact
https://www.wordfence.com/threat-intel/vulnerabilities/submit
## Policy
[INSERT YOUR POLICY URL FROM STEP 1]
## Bounty Eligibility
https://www.wordfence.com/threat-intel/bug-bounty-program/
## Acknowledgements
https://www.wordfence.com/threat-intel/vulnerabilities/researchers/

We take the security of our software very seriously. If you discover any security vulnerabilities within our project, please report them through Wordfence. To submit a vulnerability report for [Software Name], kindly complete the form available at https://www.wordfence.com/threat-intel/vulnerabilities/submit.

Depending on the nature of the vulnerability, you may be eligible for a bounty through the Wordfence Bug Bounty Program. The program's scope eligibility can be reviewed here: https://www.wordfence.com/threat-intel/bug-bounty-program/#scope.
					

Step 3: Update your software's readme.txt file

Add the following text to your software's readme.txt file:

###Reporting Security Issues
Please report all vulnerabilities found in this software using the Wordfence Vulnerability Submission form at [https://www.wordfence.com/threat-intel/vulnerabilities/submit/]
					

That's it! Once these steps are completed, researchers will be able to quickly find that any new vulnerabilities discovered in your software should be submitted through the Wordfence Bug Bounty Program. Our team will provide free validation before you receive notification. Additionally, Wordfence will reward researchers with bug bounty rewards for vulnerabilities in-scope of our program.

Currently, the Wordfence Vulnerability Management Portal is invite-only. Please register your interest with this form to request an invitation. We are working towards making the platform more broadly accessible in the future.

There are no special requirements to sign up. Any vendor of a currently active WordPress plugin or theme is eligible to request an invite and sign up. We prioritize vendors who are committed to addressing security vulnerabilities in a timely manner.

Yes, both free and paid WordPress plugins and themes are eligible to register for the Wordfence Vulnerability Management Portal. Our goal is to provide a centralized platform for all WordPress vendors to effectively manage vulnerabilities.

While direct export functionality is not currently available, we understand the value of being able to analyze and manage your vulnerability data offline or integrate it with other systems. We are actively exploring options for future export capabilities and will provide updates as they become available. In the meantime, all vulnerability report details are readily accessible within the portal for review and management.

Timely communication and action on submitted vulnerabilities are crucial for maintaining the security of your software and the WordPress ecosystem. If a submitted vulnerability is validated and we do not receive a response within a reasonable timeframe, we may take the following steps:

  • Continued Notifications: We will send reminder notifications to the contact email addresses provided during registration.
  • Public Disclosure Consideration: As outlined in the Wordfence Security Policy, if a vendor is unresponsive to a validated and critical vulnerability after a reasonable period, we may proceed with public disclosure to protect WordPress users.
  • Impact on Bug Bounty Rewards: Researchers who submit valid vulnerabilities are eligible for rewards through the Wordfence Bug Bounty Program. A lack of vendor responsiveness may impact the reward process.

We strongly encourage vendors to actively monitor the Vulnerability Management Portal and respond to submissions promptly to ensure the security of their products and maintain a collaborative relationship within the WordPress security community.

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation