Skip to content
August 18, 2025

Free Websites, share News and Posts publicly

Primary Menu
  • Registration free websites/as writer
  • Login
Live
  • Home
  • [New post] Wordfence Launches Bug Bounty Program
  • news

[New post] Wordfence Launches Bug Bounty Program

alisa November 10, 2023 4 min read
Site logo image Sarah Gooding posted: ” Wordfence launched a bug bounty program today to provide financial incentive for security researchers reporting high risk vulnerabilities to the company’s program. After researchers disclose vulnerabilities to Wordfence, the company triages them and c” WP Tavern

Wordfence Launches Bug Bounty Program

0bce5db7a60aebfe02859e1f166195737a6a823d6aaa45dfaccc668744d804d0?s=96&d=retro&r=R

Sarah Gooding

Nov 9

Wordfence launched a bug bounty program today to provide financial incentive for security researchers reporting high risk vulnerabilities to the company’s program.

After researchers disclose vulnerabilities to Wordfence, the company triages them and confidentially discloses them to the vendors to fix. When the fix is released, the vulnerability will be included in Wordfence’s public database, which is free to access, following a responsible disclosure policy.

“There is no cap on the rewards an individual researcher can earn, and every single in-scope vulnerability received via our submissions process earns a reward bounty,” Wordfence security analyst Chloe Chamberland said.

Wordfence will reward researchers who discover vulnerabilities in plugins and themes with 50,000+ active installations. A few examples of the payouts include the following:

  • $1,600 for an Unauthenticated Arbitrary File Upload, a Remote Code Execution, a Privilege Escalation to Admin, or an Arbitrary Options Update in a plugin or theme with over one million active installations.
  • $1,060 for an Unauthenticated Arbitrary File Deletion in a plugin or theme with over one million active installations, assuming wp-config.php can easily be deleted.
  • $800 for an Unauthenticated SQL Injection in a plugin or theme with over one million active installations.
  • $320 for an Unauthenticated Cross-Site Scripting vulnerability in a plugin or theme with over one million active installations.
  • $80 for a Cross-Site Request Forgery vulnerability in a plugin or theme with over one million active installations, and a significant impact.

“Our Bug Bounty Program has been designed to have the greatest positive impact on the security of the WordPress ecosystem,” Chamberland said. “Rewards are not earned by bulk hunting for vulnerabilities with minimal impact and earning a place on a leaderboard, but rather, they are based on active install counts, the criticality of the vulnerability, the ease of exploitation, and the prevalence of the vulnerability type.”

Wordfence’s bug bounty program launch was clearly vying for competitive positioning by indirectly calling out Patchstack, which operates its program on a leaderboard system where only the top researchers get paid. There are a few notable differences, where some bounties are awarded by discretion but most individual bounties are for the highest score in various categories:

Patchstack guarantees a monthly prize pool of at least $2425 (the lowest possible prize pool). Patchstack Alliance member who will collect the most points for a particular month from their submitted reports will get the $650 bounty, the second place will get $350 and the third will get $250.

We have extra bounties (single bounties) for reporting the vulnerability with the highest CVSS ver. 3.1 base score; the highest active install count; and for reporting a group of components affected by the same vulnerability.

Patchstack can reward individual Patchstack Alliance members at their discretion based on the overall impact of the vulnerabilities they discover.

Wordfence is taking a different approach in paying for every vulnerability reported within the scope identified by the program.

Researchers in the WordPress ecosystem should familiarize themselves with the various bug bounty programs and determine the best avenue for their disclosures. Some plugins and companies, such as Elementor, Brainstorm Force, Automattic, Castos, and WP Engine, have their own bug bounty programs, with a range of different payouts.

“We pay more per vulnerability and we pay for every valid vulnerability submitted,” Wordfence CEO Mark Maunder said. “We feel this is the only fair way to do it because gamification of a vulnerability program is like having employees who all work, but only those at the top of the leaderboard get paid. If you submit a valid vulnerability, you should get paid for your work.”

Maunder contends that the wrong incentives are driving down the quality of the research submitted.

“There are an extremely high number of low risk and low quality vulnerabilities being submitted to databases like Patchstack,” he said. “Vulnerabilities that involve a Cross-Site Request Forgery are an example of this. The incentives we are seeing out there encourage researchers to generate a a high volume of low risk vulnerabilities to get rewarded. These high numbers are then used to market security products.”

Maunder said Wordfence has structured its program around shifting the incentives to reward research into high risk vulnerabilities, instead of ramping up the marketing metrics for a particular vulnerability database.

“A high volume of low risk vulnerabilities in any particular database harms the industry because it creates work for other organizations who have to integrate this data, but for the most part it is useless noise that we are forced to sift through, rather than representing any real-world risk to the user community,” Maunder said.

As the newcomer to the group of WordPress companies offering bug bounties, Wordfence is entering the market with the intention of attracting more reports through additional bonuses (10% for the first 6 months) and a bonus structure that rewards chaining multiple vulnerabilities together, thorough documentation, and other extra efforts.

Not every author of a popular plugin or theme can afford to offer their own bug bounty program, and this is where security companies are stepping in to fill in the gaps. More competition across companies for high quality research can only be good for WordPress users, as it provides more incentive for securing the ecosystem and will potentially attract more skilled researchers. The bug bounty programs will likely evolve over time as companies refine them to provide the best value for original research.

Comment

Manage your email settings or unsubscribe.

Trouble clicking? Copy and paste this URL into your browser:
https://wptavern.com/wordfence-launches-bug-bounty-program

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. – 60 29th St. #343, San Francisco, CA 94110  

t.gif?has featured image=0&subscriber id=530390941& ui=8ba62ef4a9e9a49d3fe3da3d5a99ce4d& ut=anon&email domain=gmail.com&blog id=9006382&post id=151186&user email=gjjtuyu768%40gmail.com&date sent=2023 11 10&email id=3b0a1b0b961aa37d66f7a9b3d7070168&email name=new post&template=new post& en=wpcom email open&browser type=php agent& aua=wpcom tracks client v0 b.gif?blog=9006382&post=151186&subd=wptavern.com&ref=&email=1&email o=jetpack&host=wptavern

Chat read-only to anonymous users. Chat with Anyone and Anywhere. Only registered users are allowed to send messages.
Loading the chat ...
119844 Register Login

Continue Reading

Previous: Buletin Berita VOA – 10.11.2023
Next: Forward Singapore shows the emerging contours of 4G leadership style

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

verde two
VERDE TWO Apartment sale
  • actress and actor
  • Afghanistan
  • airlines
  • amazon
  • America
  • android
  • apache
  • apple
  • Arab
  • australia
  • Australian Embassy
  • automotive
  • bahan bangunan
  • Bali island
  • Ban
  • banking
  • bearing
  • Brazil
  • Brunei Darussalam
  • business
  • canada
  • casino
  • China
  • cloud
  • cloudflare
  • cPanel
  • cruise
  • crypto currency
  • culture
  • currency
  • DNS
  • docker
  • eCommerce
  • economy
  • education
  • Email
  • Energy
  • england
  • entertainment
  • environment
  • Fashion
  • finance
  • Food
  • France
  • gaming
  • garden
  • Germany
  • golf
  • Golf indonesia
  • google
  • HarmonyOS
  • Health products
  • history
  • hospital
  • hotel restaurant
  • Huawei
  • human
  • IBM
  • IMF
  • india
  • Indonesia
  • instagram
  • internet
  • investment
  • Israel
  • Japan
  • jobs
  • kitchenware
  • korea
  • kubernetes
  • KVM
  • Leisure
  • limbah
  • Linux
  • Living style
  • Longhorn
  • lottery
  • machine
  • machine learning
  • machinery
  • Malaysia
  • manufacturing
  • mariadb
  • maritime
  • material building
  • medical
  • meta
  • Microsoft
  • music
  • MySQL
  • New Zealand
  • news
  • NFS
  • Nickel
  • nightclub
  • north korea
  • OBS
  • oil and gas
  • Pakistan
  • Palestine
  • Philippines
  • Photography
  • php
  • phpMyAdmin
  • private-jet
  • promotion products
  • real estate
  • Resort hotel
  • Russia
  • sanitary ware
  • search engine
  • Shopping Mal
  • singapore
  • Singapore Pools
  • software
  • south korea
  • sport
  • ssl
  • swiss
  • Technology
  • Thailand
  • tourism boards
  • travel
  • Turkish
  • Ubuntu
  • Uncategorized
  • United Arab Emirates
  • vietnam
  • virtualbox
  • virtualization
  • vmware
  • water products
  • whatsapp
  • WordPress
Register and posting news , your skills , knowledge , science , stories , experiences , etc
Copyright © All rights reserved. The tiatira is not responsible for the content of each writer / author , external sites. |