Improving WordPress security is a two-part process. It involves finding and fixing vulnerabilities, but also ensuring that reports from the community are focused on issues that have a real security impact.
The WordPress security team is currently investing more effort into the security release process, working through existing findings, and expanding proactive vulnerability research. As part of this broader initiative, the team is also updating the Vulnerability Disclosure Program guidelines. This is to ensure that both the team’s time and the time of security researchers is spent on valid vulnerabilities with clear and significant impact.
For most in-scope assets (excluding WordPress Core and Gutenberg), a change is being made. Issues that require a role like Contributor will generally no longer be eligible for a report. This is because these roles usually require administrator approval to obtain. The ability for one authenticated role to do something meant for another role will also not be enough on its own. For these to be considered, the issue must lead to a high-severity escalation. For now, WordPress Core and Gutenberg will continue to follow the existing guidelines.
Researchers are encouraged to focus their efforts on vulnerabilities with a clear security impact. This is especially true for high-severity issues. The most valuable findings are those that can be exploited without any authentication, or by low-privileged users like Subscribers.
Responsible disclosure remains a vital part of WordPress security. Issues can be reported through the official channels. By combining proactive work to find vulnerabilities with a focus on higher-impact reports, the project can spend more time on the findings that make WordPress and its ecosystem meaningfully safer.

Leave a Reply