Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/wordpress Disclosed reports analyzed: 86 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bounty data.
Work at WordPress? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 4 Oct 2026.
What it pays, by severity
$200,000 paid to researchers in total, $95,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.
Intake & responsiveness · last 90 days
Response targets it sets itself
A target the program declared, not a measurement of it being met.
Getting in the door
Over 45 days (111 snapshots): intake up 772 reports; response efficiency up 14 points; 90-day payout up $35,000.
See how this programme’s report load compares to others →
Reviews
1 publishedWho this program credits
603 creditedResearchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.
| # | Researcher | Reputation | Recognised / submitted |
|---|---|---|---|
| 1 | rafiem | 3,882 | 202 / 287 70% |
| 2 | paulos__ | 1,221 | 65 / 92 71% |
| 3 | simonscannell | 410 | 9 / 10 90% |
| 4 | hoangkien1020 | 344 | 12 / 13 92% |
| 5 | skansing | 326 | 13 / 15 87% |
| 6 | bornwinnerrr | 308 | 16 / 25 64% |
| 7 | buggedout | 272 | 3 / 4 75% |
| 8 | p4p3r_hak | 267 | 14 / 39 36% |
| 9 | karimeo | 259 | 6 / 6 100% |
| 10 | foobar7 | 205 | 9 / 10 90% |
| 10 | ysx | 90 | 5 / 5 100% |
| 11 | yuvraj_dighe | 178 | 9 / 9 100% |
| 12 | jakubk | 171 | 15 / 35 43% |
| 13 | svennergr | 136 | 3 / 3 100% |
| 14 | vvh1te3zz | 130 | 14 / 18 78% |
| 14 | argareksapatii | 119 | 7 / 12 58% |
| 15 | jdgrimes | 113 | 5 / 6 83% |
| 16 | codertom | 112 | 7 / 9 78% |
| 17 | evanricafort | 108 | 6 / 17 35% |
| 18 | ducnt_ | 103 | 3 / 3 100% |
| 18 | kolchylilah | 103 | 7 / 10 70% |
| 20 | hanno | 98 | 4 / 5 80% |
| 20 | mopman | 98 | 4 / 4 100% |
| 22 | mickey_cyberkid | 96 | 5 / 5 100% |
| 22 | opnsec | 96 | 2 / 2 100% |
Showing the top 25 of 603 credited on HackerOne.
Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 30 Sep 2026.
Beautiful sites of any kind.
Scope
37 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.buddypress.org,bbpress.org,profiles.wordpress.org | WILDCARD | ✓ bounty | Critical |
| *.trac.wordpress.org, *.svn.wordpress.org, *.git.wordpress.org | SOURCE CODE | ✓ bounty | Critical |
| *.trac.wordpress.org, *.svn.wordpress.org, *.git.wordpress.org, github.com/WordPress | SOURCE CODE | ✓ bounty | Critical |
| *.wordcamp.org | WILDCARD | ✓ bounty | Critical |
| *.wordpress.net | WILDCARD | ✓ bounty | Low |
Show all 37 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.wordpress.org | WILDCARD | ✓ bounty | Critical |
| api.wordpress.org | URL | ✓ bounty | Critical |
| bbPress Core | SOURCE CODE | ✓ bounty | Critical |
| BuddyPress Core | SOURCE CODE | ✓ bounty | Critical |
| codex.wordpress.org,codex.bbpress.org,codex.buddypress.org | URL | ✓ bounty | Medium |
| Create Block Theme | SOURCE CODE | ✓ bounty | Critical |
| doaction.org | URL | ✓ bounty | Critical |
| github.com/wordpress | SOURCE CODE | ✓ bounty | Critical |
| GlotPress | SOURCE CODE | ✓ bounty | Critical |
| Gutenberg | SOURCE CODE | ✓ bounty | Critical |
| gutenberg.run | URL | ✓ bounty | Low |
| mercantile.wordpress.org | URL | ✓ bounty | Medium |
| Official WordPress plugins | SOURCE CODE | ✓ bounty | Critical |
| planet.wordpress.org | URL | ✓ bounty | Critical |
| Playground | SOURCE CODE | ✓ bounty | Critical |
| Secure Custom Fields | SOURCE CODE | ✓ bounty | Critical |
| SQLite Database Integration | SOURCE CODE | ✓ bounty | Critical |
| WordPress Core | SOURCE CODE | ✓ bounty | Critical |
| wordpressfoundation.org | URL | ✓ bounty | Medium |
| WP-CLI | SOURCE CODE | ✓ bounty | Critical |
| *.wordpress.com | WILDCARD | out | None |
| 335703880 | APPLE STORE APP ID | out | None |
| Archived GitHub repositories | OTHER | out | None |
| Digital Ocean, AWS, etc | OTHER | out | None |
| https://github.com/wordpress-mobile/ | SOURCE CODE | out | None |
| https://github.com/wordpress-mobile/WordPress-iOS | SOURCE CODE | out | None |
| irclogs.wordpress.org | URL | out | None |
| lists.wordpress.org | URL | out | None |
| munin-*.wordpress.org | WILDCARD | out | None |
| org.wordpress.android | GOOGLE PLAY APP ID | out | None |
| status.wordpress.org,glotpress.blog,wordpress.tv | URL | out | None |
| wordpress.tv | URL | out | None |
Log in to comment