PentestingHere
Log in Join

WordPress

WordPress on HackerOne · HackerOne Active

Official page

Scope

At a glance

  • Bounties: Yes
  • Swag: No
  • Managed by the platform: No
  • Average first response: Not published
  • Average time to resolution: Not published

In scope

  • *.buddypress.org,bbpress.org,profiles.wordpress.org
  • *.trac.wordpress.org, *.svn.wordpress.org, *.git.wordpress.org, github.com/WordPress
  • *.wordcamp.org
  • *.wordpress.net
  • *.wordpress.org
  • BuddyPress Core
  • GlotPress
  • Gutenberg
  • Official WordPress plugins
  • WP-CLI
  • WordPress Core
  • api.wordpress.org
  • bbPress Core
  • codex.wordpress.org,codex.bbpress.org,codex.buddypress.org
  • doaction.org
  • irclogs.wordpress.org
  • lists.wordpress.org
  • mercantile.wordpress.org
  • munin-*.wordpress.org
  • planet.wordpress.org
  • wordpressfoundation.org

Out of scope

  • *.wordpress.com
  • 335703880
  • Archived GitHub repositories
  • Digital Ocean, AWS, etc
  • https://github.com/wordpress-mobile/
  • org.wordpress.android
  • status.wordpress.org,glotpress.blog,wordpress.tv

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback