Vulnerability Reporting Program

Scope of Vulnerability Reporting Program

Any vulnerability that could negatively impact confidential data discovered in a WPSec application, API, or content found on wpsec.com or any associated domains will be eligible for inclusion in the program. Any research or testing that might affect the availability, or degrade the performance, of the WPSec services is strictly prohibited.

Read more out of scope bugs below.

Safe Harbor

WPSec considers security research and vulnerability disclosure conducted in good faith and in accordance with this policy to be authorized. We will not pursue or support legal action against researchers who act in good faith, only interact with accounts they own or have explicit permission to access, make every effort to avoid privacy violations, data destruction, and interruption or degradation of our services, and give us a reasonable opportunity to resolve an issue before any public disclosure. If a third party initiates legal action against you for activities conducted in accordance with this policy, we will make our authorization known. If you are ever unsure whether your testing is consistent with this policy, contact us at security [at] wpsec [dot] com before proceeding.

How to Report an Issue

If you believe you have found a security flaw in our software, please contact security [at] wpsec [dot] com using our PGP-key (below). We ask you do not publicly disclose suspected vulnerabilities until we have confirmed a fix is available. Please include your preferred contact method, and enough details to allow us to efficiently reproduce the issue. You can use our PGP public key (below) to encrypt your communications to us. Contact us if you have any questions about our responsible disclosure policy, or refer to the OWASP Vulnerability Disclosure Cheat Sheet for general best practices for security researchers.

Response and Recognition

We will investigate and get back to you as soon as possible, usually within one or two business days. If you are interested in helping find the solution, let us know and we’ll involve you as much as we can. To acknowledge the first person who alerts us to a previously unknown and non-trivial security issue, we show our appreciation by adding their name to the Acknowledgments section on this page, and offer them a cool WPSec Vulnerability T-shirt.

We’ll ask you for:

Your name, website, and handle as you’d like it displayed on this page. Your shipping address and T-shirt size.

Acknowledgements

We thank these people and organizations for making our service more secure:

  • No one yet — be the first.

Out of scope

 * Issues related to software not under WPSec control such as E-mail clients
 * Reports from automated web vulnerability scanners that are not validated
 * Issues that need social engineering for successful exploitation
 * Any physical attempts against WPSec property or data centers
 * Social engineering attacks against WPSec employees
 * Missing autocomplete attributes
 * Missing security flags on non-security-sensitive cookies
 * Username or Email enumeration
 * Session errors - Such as invalidating sessions on logout or password change
 * Missing Best practices
 * Spamming
 * Issues that require physical access to a victim’s computer for successful exploitation.
 * Open ports without an accompanying proof-of-concept demonstrating vulnerability.
 * XSS issues that affect only outdated browsers.
 * Tab nabbing and window.opener-related issues.
 * Issues related to absence of CAA DNS record.
 * Discrepancy related to permissions for owner and moderator role. 
 * Phishing using Open Redirection. Exceptions: Open redirection that leads to leakage of OAuth Access Token, bypass of Content Security Policy,etc.
 * Content Spoofing / Content Injection issues
 * Banner grabbing issues (Finding info like webserver name, etc.)
 * Cross-site Request Forgery (CSRF)
 * Issues related to SPF, DKIM and DMARC
 * Reflected File Download
 * Error Stack Trace or 401/403/500 Server error without an accompanying evidence of vulnerability
 * Self-XSS including cases where user himself pastes javascript code into the browser.
 * Issues without clearly identified security impact, such as clickjacking on a static website, descriptive error messages, HTTP OPTIONS method enabled, etc.
 * Issues related to Payment Fraud.
 * Business logic errors, such as bypassing premium features, plan or account limits, and other workflow abuse. Exception: logic flaws that expose another user's confidential data are in scope.
 * Issues related to Mixed Content
 * iframe/frame related bugs
 * Clickjacking (we're actively working on this)
 * Brute Force protections

Automated Scanning

If you employ automated scanning tools, their requests must be rate limited to not exceed 3 requests per second without prior approval. Failure to do so may be considered a DoS attack and will result in disqualification from the program.

Automated vulnerability scanners commonly have low priority issues and/or false positives. Before submitting the results from a scanner, please take a moment to confirm that the reported issues are actually valid and exploitable. Please submit an issue only if you have exploited a real vulnerability.

PGP Key

Use the key below when reporting vulnerabilities to security [at] wpsec [dot] com, thanks.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBF5KTFIBEADRvxOAHWw/4xG1BBZvJiA8FXIC/2nu65CMVwyvWVgWkPskRi5A
WcVvBDXUOkIzCliTi8Fq9qEgg9/VT7QjBBVlVXNGHI1Ps4VSQHjHFAjRjl8cfT6k
j4NaOzDQk3G8k0y1+nAI5etDEMdDjCV1A2DQd6w8i15MJnKe2tax7DdGa6jh262s
gByhyBmPlA3mww0qFSl3Fq6hQJPR+S9sLldT87IU/VNx7dbhj3gW+/DTS7CECwoU
3D3VGllo5xnY8upGnKqpJtyF82LElaWhANpOveCQu+fDrD/NiO47aOZd9XMqQaM9
Zavxs9mVWj7GZKFwfXM4EfXz4/MPH90/txODL/t8CDuH+YG3rFec9VyFjpunQHbE
5pvGiIdBhasEc6dbtpEbu2gsNpB1CsOCt85Nijyswlga74gI/RP7m+1xrnhytvxG
cAqFpBt3woJprlX5W8CgxnVt4c5I7pf18+k31/UyBP1v4rkp06YUD/No5Np7BN4+
L4a/HvlR5fHgFV1G/kisntD/GzornA49KhAzZo+x+2Wc3RUo3CA+p02S2k0GbqwZ
OV3Viz95Bcn9Yyf70g46O7bfcvGCzGvBF/fugLvki3Mzs/IjwhU2avSjWWrng41x
dXh+b/eiVkiTFNn0zBSeGLu9Zj8oUg38YFiu+FsLxwDNdDuFazizAQcMyQARAQAB
tB9pbmZvQHdwc2VjLmNvbSA8aW5mb0B3cHNlYy5jb20+iQJOBBMBCAA4FiEE9j56
lg+CHdscu3AgolR2fx1VW3wFAl5KTFICGwMFCwkIBwIGFQoJCAsCBBYCAwECHgEC
F4AACgkQolR2fx1VW3yXVw//cEgp+UeWYihWDjNtVtBPgoba4EdFnLvvpdv7gOSe
zQpZyxJOhft7CIclyP8gLHSEol49EFCgZQn9epVMD+DN6LF2ljw/TYPxfzVOMWRv
IrJ8ODJJqtzemM9kovwgORK0AUuX1GoQx088WVydmLH12sWBqGIMrQbzVI46PpBl
LDzS42mm7EpDXgcEcTKWomsCR9bEasqF8TkZitFDXEjacuVtM2Ty/OeLdwPovWFB
L47qrENbNkOke92bdT2I8wfW+jW8F8gFPfUW25Y31LgelbGdnFLrqC2WvTxfJWMP
fAu74X4KwBlV1c79F3Ii2m5q8NCQiAAhscf423No+5QXzFEMiO+CbbXsL/8fvOxA
KvLAJbsibgZoqsv8a4okYyw8bXVfyZkE0GU7I6+cr5NZrV7NJqOnUHiS3jbFdJDa
S7tWByc91eeD831I03D1YwjxIvOu+tESkvsWjqCqtsi4485oLMb9/V8MsGVEF5lT
z3WKBG69tGwdmvjTKjc9UbXdJiLHrnSVdiBvF+fIlGmtbI5RkXOafKNY7/oii30s
XrA6Xp/mxbXynUsuQ4ur+E0kVqNl7n/33RgLlbAcChk7P03Mkk61jOzjEiH0KE81
7vocN+4nLkUyV/Cw03kq/YBY+/82SU2NMRkFjd/HSFu67aBWnhercsJecyb2QKny
sYi5Ag0EXkpMUgEQAMoHoDIpl+Hv1L8bgO0daZ7hc44YZ+KvckWMLrbaARm6qGAm
1V5Rt5Ek2SCtA2QB9awjYo/RO0qdgC0uCAe/tZstM4/G1fbLLGRBuorVXs76Ykir
fZNPHnxIdLp+k4oD0/QqtVeWWXUbQl9KeRpYanXVd7lEWKtJoTzVe4uN/v9DLKLU
yQsbBYXAcOW5MHSI9M6vY+OA3+hPEg6JTmfde/E4hr+CdFgthk+LQq9YXPWvyEHF
3OZDp1fwtXrWq+SertmtggRhGtNdvCypifyWSHQQ9elbsXbgqbbaqCXJGv13NowO
v3B3BBdX8NLYUYoIWeN6rM5TYf54LeWoI4Gm01yIwNlKTY5Q7wYNCWN6AjTYXz2w
0FDWnfL7uC9M66xREtdHO4oW4uK/oqbAPvxb+WcTLSLo2bG80liV9jx8KJiAXyLy
sWlkQ/V/DHS19P6RhaXVwoM1mUvf9YoWWQrXArt1MKbPse3y++pUBx8OClYkLny1
E2RmhqBDF4GLiaq43M05j+B52/ZU2VchJoTkvvKok5Gm/YJ2rYeexCso2cCQASCp
bDjumrBn0FVPbgkuiCt8xIUEgxYQciiW1SfhSZcqXgOu3AUwKLAr4Jy0HjTQb2QL
mjDSEhKQywuMx6e6g/Uer0fPEPFUNBCNyiaUnJTO+e1SvUJq3KopWfjFcB93ABEB
AAGJAjYEGAEIACAWIQT2PnqWD4Id2xy7cCCiVHZ/HVVbfAUCXkpMUgIbDAAKCRCi
VHZ/HVVbfFYID/0Qs2es4PA0MH1+ZHLeACu00KcmY0pW0qCvnREvzNd39Z8TLu6j
TQzDyzpCcA7LImcHbApIjWV3Z3OHJceXdZ8AqxrLXxmEdJNFyC2dOwAhvyMf3CQQ
9H23b7QdkSINq5Jv4XNEk2sDMPaz1AlKbM80T0MviZNuTWPDcUGbuxtT1PYxqwTQ
H6O7hJqQHejH24WRY+xOF8GgMyDuHsO3/uNobi5DHS2dCJpJVLWOIbiKAMzsGXwJ
3Oz/96EeCbM7fr+s/3EreXGIuOtteIDP1Qefi0C2wivrg6QE+eapOqkMgBHjx7b9
LJi6aFu6LcWDKpmnQcHOaFKfYM1hvkyISqmCW0EXFRep1/i6Xc5TLyoLjZ4xgUZN
FsSWWgAvR6mZ6GccwNwQISg5bS0MqtOn0TZXuwMf0+t7m/8YJ+ATPA7x3op2IuIr
zP0BxJlAHwtaCDaroyqnVLZOEx1uKpH6RvSGzV4BBRgI2bbaLCrLVUTBKZ1GHZt4
ynw0U3PUjyYuhqDjPXP2+nryW88fh4ea9z/P9qqy1PYJ2AWh7eqswuWK8NfgAN22
5MRwEaD0Qetz0YTiDso+1QrUzP34W71jQ+8kwQUaqRKwd4keNeHbFpdDuB/75yS5
BPTta6q43xloWdLLglw/WjppWxsH6R6dQy9wqwWlWtN4gloQDCHp7/bZKw==
=GYD2
-----END PGP PUBLIC KEY BLOCK-----