Responsible Disclosure
How to report a WordPress plugin or theme vulnerability to WPDeeply.
If you have found a vulnerability in a WordPress plugin or theme and want it documented here, this is how that works.
Report a vulnerability
Email legal@wpdeeply.com with the subject line “Disclosure”. Encrypted mail is welcome; ask and we will exchange keys before you send details.
Information required
- Affected plugin or theme, with its WordPress.org slug.
- Affected version, and the newest version you confirmed as affected.
- Vulnerability type and the privilege level required to exploit it.
- Reproduction steps against a clean WordPress installation.
- A proof of concept where one is appropriate — no live third-party sites.
- How you want to be credited, and any handle or URL to credit.
Disclosure process
- We acknowledge receipt within five working days.
- We reproduce the issue locally before doing anything else.
- The vendor is contacted first, with a coordinated timeline.
- Publication follows a patched release, or 90 days after vendor contact if no fix appears and users are better served by knowing.
- If the vendor cannot be reached, we notify the WordPress.org plugins team.
Researcher credit
The researcher is named in the disclosure and in the plugin profile timeline, unless they ask not to be. WPDeeply does not publish other people’s findings under its own name — the existing archive is credited to Slavco Mihajloski (mslavco) for exactly this reason.
What we do not offer
There is no bug bounty. There is no payment. What there is: careful verification, vendor coordination, permanent credit and a page that stays online.
Reporting a vulnerability in WPDeeply itself
See security. Same address, same timeline, and we would rather hear it from you than from a scan of our logs.