Reporting Security Vulnerabilities

The WordPress project attempts to be as proactive as possible in preventing security problems from being introduced, but does not assume they’ll never come up. It is standard practice to responsibly and privately disclose security vulnerabilities directly to the vendor (the WordPress core development team, in this case) so a fix can be coordinated and … Continue reading Reporting Security Vulnerabilities