Vulnerability Reporting Program
Scope of Vulnerability Reporting Program
Any vulnerability that could negatively impact confidential data discovered in a WPSec application, API, or content found on wpsec.com or any associated domains will be eligible for inclusion in the program. Any research or testing that might affect the availability, or degrade the performance, of the WPSec services is strictly prohibited.
Read more out of scope bugs below.
Safe Harbor
WPSec considers security research and vulnerability disclosure conducted in good faith and in accordance with this policy to be authorized. We will not pursue or support legal action against researchers who act in good faith, only interact with accounts they own or have explicit permission to access, make every effort to avoid privacy violations, data destruction, and interruption or degradation of our services, and give us a reasonable opportunity to resolve an issue before any public disclosure. If a third party initiates legal action against you for activities conducted in accordance with this policy, we will make our authorization known. If you are ever unsure whether your testing is consistent with this policy, contact us at security [at] wpsec [dot] com before proceeding.
How to Report an Issue
If you believe you have found a security flaw in our software, please contact security [at] wpsec [dot] com using our PGP-key (below). We ask you do not publicly disclose suspected vulnerabilities until we have confirmed a fix is available. Please include your preferred contact method, and enough details to allow us to efficiently reproduce the issue. You can use our PGP public key (below) to encrypt your communications to us. Contact us if you have any questions about our responsible disclosure policy, or refer to the OWASP Vulnerability Disclosure Cheat Sheet for general best practices for security researchers.
Response and Recognition
We will investigate and get back to you as soon as possible, usually within one or two business days. If you are interested in helping find the solution, let us know and we’ll involve you as much as we can. To acknowledge the first person who alerts us to a previously unknown and non-trivial security issue, we show our appreciation by adding their name to the Acknowledgments section on this page, and offer them a cool WPSec Vulnerability T-shirt.
We’ll ask you for:
Your name, website, and handle as you’d like it displayed on this page. Your shipping address and T-shirt size.
Acknowledgements
We thank these people and organizations for making our service more secure:
- No one yet — be the first.
Out of scope
* Issues related to software not under WPSec control such as E-mail clients * Reports from automated web vulnerability scanners that are not validated * Issues that need social engineering for successful exploitation * Any physical attempts against WPSec property or data centers * Social engineering attacks against WPSec employees * Missing autocomplete attributes * Missing security flags on non-security-sensitive cookies * Username or Email enumeration * Session errors - Such as invalidating sessions on logout or password change * Missing Best practices * Spamming * Issues that require physical access to a victim’s computer for successful exploitation. * Open ports without an accompanying proof-of-concept demonstrating vulnerability. * XSS issues that affect only outdated browsers. * Tab nabbing and window.opener-related issues. * Issues related to absence of CAA DNS record. * Discrepancy related to permissions for owner and moderator role. * Phishing using Open Redirection. Exceptions: Open redirection that leads to leakage of OAuth Access Token, bypass of Content Security Policy,etc. * Content Spoofing / Content Injection issues * Banner grabbing issues (Finding info like webserver name, etc.) * Cross-site Request Forgery (CSRF) * Issues related to SPF, DKIM and DMARC * Reflected File Download * Error Stack Trace or 401/403/500 Server error without an accompanying evidence of vulnerability * Self-XSS including cases where user himself pastes javascript code into the browser. * Issues without clearly identified security impact, such as clickjacking on a static website, descriptive error messages, HTTP OPTIONS method enabled, etc. * Issues related to Payment Fraud. * Business logic errors, such as bypassing premium features, plan or account limits, and other workflow abuse. Exception: logic flaws that expose another user's confidential data are in scope. * Issues related to Mixed Content * iframe/frame related bugs * Clickjacking (we're actively working on this) * Brute Force protections
Automated Scanning
If you employ automated scanning tools, their requests must be rate limited to not exceed 3 requests per second without prior approval. Failure to do so may be considered a DoS attack and will result in disqualification from the program.
Automated vulnerability scanners commonly have low priority issues and/or false positives. Before submitting the results from a scanner, please take a moment to confirm that the reported issues are actually valid and exploitable. Please submit an issue only if you have exploited a real vulnerability.
PGP Key
Use the key below when reporting vulnerabilities to security [at] wpsec [dot] com, thanks.
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBF5KTFIBEADRvxOAHWw/4xG1BBZvJiA8FXIC/2nu65CMVwyvWVgWkPskRi5A WcVvBDXUOkIzCliTi8Fq9qEgg9/VT7QjBBVlVXNGHI1Ps4VSQHjHFAjRjl8cfT6k j4NaOzDQk3G8k0y1+nAI5etDEMdDjCV1A2DQd6w8i15MJnKe2tax7DdGa6jh262s gByhyBmPlA3mww0qFSl3Fq6hQJPR+S9sLldT87IU/VNx7dbhj3gW+/DTS7CECwoU 3D3VGllo5xnY8upGnKqpJtyF82LElaWhANpOveCQu+fDrD/NiO47aOZd9XMqQaM9 Zavxs9mVWj7GZKFwfXM4EfXz4/MPH90/txODL/t8CDuH+YG3rFec9VyFjpunQHbE 5pvGiIdBhasEc6dbtpEbu2gsNpB1CsOCt85Nijyswlga74gI/RP7m+1xrnhytvxG cAqFpBt3woJprlX5W8CgxnVt4c5I7pf18+k31/UyBP1v4rkp06YUD/No5Np7BN4+ L4a/HvlR5fHgFV1G/kisntD/GzornA49KhAzZo+x+2Wc3RUo3CA+p02S2k0GbqwZ OV3Viz95Bcn9Yyf70g46O7bfcvGCzGvBF/fugLvki3Mzs/IjwhU2avSjWWrng41x dXh+b/eiVkiTFNn0zBSeGLu9Zj8oUg38YFiu+FsLxwDNdDuFazizAQcMyQARAQAB tB9pbmZvQHdwc2VjLmNvbSA8aW5mb0B3cHNlYy5jb20+iQJOBBMBCAA4FiEE9j56 lg+CHdscu3AgolR2fx1VW3wFAl5KTFICGwMFCwkIBwIGFQoJCAsCBBYCAwECHgEC F4AACgkQolR2fx1VW3yXVw//cEgp+UeWYihWDjNtVtBPgoba4EdFnLvvpdv7gOSe zQpZyxJOhft7CIclyP8gLHSEol49EFCgZQn9epVMD+DN6LF2ljw/TYPxfzVOMWRv IrJ8ODJJqtzemM9kovwgORK0AUuX1GoQx088WVydmLH12sWBqGIMrQbzVI46PpBl LDzS42mm7EpDXgcEcTKWomsCR9bEasqF8TkZitFDXEjacuVtM2Ty/OeLdwPovWFB L47qrENbNkOke92bdT2I8wfW+jW8F8gFPfUW25Y31LgelbGdnFLrqC2WvTxfJWMP fAu74X4KwBlV1c79F3Ii2m5q8NCQiAAhscf423No+5QXzFEMiO+CbbXsL/8fvOxA KvLAJbsibgZoqsv8a4okYyw8bXVfyZkE0GU7I6+cr5NZrV7NJqOnUHiS3jbFdJDa S7tWByc91eeD831I03D1YwjxIvOu+tESkvsWjqCqtsi4485oLMb9/V8MsGVEF5lT z3WKBG69tGwdmvjTKjc9UbXdJiLHrnSVdiBvF+fIlGmtbI5RkXOafKNY7/oii30s XrA6Xp/mxbXynUsuQ4ur+E0kVqNl7n/33RgLlbAcChk7P03Mkk61jOzjEiH0KE81 7vocN+4nLkUyV/Cw03kq/YBY+/82SU2NMRkFjd/HSFu67aBWnhercsJecyb2QKny sYi5Ag0EXkpMUgEQAMoHoDIpl+Hv1L8bgO0daZ7hc44YZ+KvckWMLrbaARm6qGAm 1V5Rt5Ek2SCtA2QB9awjYo/RO0qdgC0uCAe/tZstM4/G1fbLLGRBuorVXs76Ykir fZNPHnxIdLp+k4oD0/QqtVeWWXUbQl9KeRpYanXVd7lEWKtJoTzVe4uN/v9DLKLU yQsbBYXAcOW5MHSI9M6vY+OA3+hPEg6JTmfde/E4hr+CdFgthk+LQq9YXPWvyEHF 3OZDp1fwtXrWq+SertmtggRhGtNdvCypifyWSHQQ9elbsXbgqbbaqCXJGv13NowO v3B3BBdX8NLYUYoIWeN6rM5TYf54LeWoI4Gm01yIwNlKTY5Q7wYNCWN6AjTYXz2w 0FDWnfL7uC9M66xREtdHO4oW4uK/oqbAPvxb+WcTLSLo2bG80liV9jx8KJiAXyLy sWlkQ/V/DHS19P6RhaXVwoM1mUvf9YoWWQrXArt1MKbPse3y++pUBx8OClYkLny1 E2RmhqBDF4GLiaq43M05j+B52/ZU2VchJoTkvvKok5Gm/YJ2rYeexCso2cCQASCp bDjumrBn0FVPbgkuiCt8xIUEgxYQciiW1SfhSZcqXgOu3AUwKLAr4Jy0HjTQb2QL mjDSEhKQywuMx6e6g/Uer0fPEPFUNBCNyiaUnJTO+e1SvUJq3KopWfjFcB93ABEB AAGJAjYEGAEIACAWIQT2PnqWD4Id2xy7cCCiVHZ/HVVbfAUCXkpMUgIbDAAKCRCi VHZ/HVVbfFYID/0Qs2es4PA0MH1+ZHLeACu00KcmY0pW0qCvnREvzNd39Z8TLu6j TQzDyzpCcA7LImcHbApIjWV3Z3OHJceXdZ8AqxrLXxmEdJNFyC2dOwAhvyMf3CQQ 9H23b7QdkSINq5Jv4XNEk2sDMPaz1AlKbM80T0MviZNuTWPDcUGbuxtT1PYxqwTQ H6O7hJqQHejH24WRY+xOF8GgMyDuHsO3/uNobi5DHS2dCJpJVLWOIbiKAMzsGXwJ 3Oz/96EeCbM7fr+s/3EreXGIuOtteIDP1Qefi0C2wivrg6QE+eapOqkMgBHjx7b9 LJi6aFu6LcWDKpmnQcHOaFKfYM1hvkyISqmCW0EXFRep1/i6Xc5TLyoLjZ4xgUZN FsSWWgAvR6mZ6GccwNwQISg5bS0MqtOn0TZXuwMf0+t7m/8YJ+ATPA7x3op2IuIr zP0BxJlAHwtaCDaroyqnVLZOEx1uKpH6RvSGzV4BBRgI2bbaLCrLVUTBKZ1GHZt4 ynw0U3PUjyYuhqDjPXP2+nryW88fh4ea9z/P9qqy1PYJ2AWh7eqswuWK8NfgAN22 5MRwEaD0Qetz0YTiDso+1QrUzP34W71jQ+8kwQUaqRKwd4keNeHbFpdDuB/75yS5 BPTta6q43xloWdLLglw/WjppWxsH6R6dQy9wqwWlWtN4gloQDCHp7/bZKw== =GYD2 -----END PGP PUBLIC KEY BLOCK-----
