Improving the security of WordPress means both finding and fixing vulnerabilities proactively, and making sure the reports we receive through responsible disclosure are focused on issues with meaningful security impact.
As part of the broader work underway through the Core Security Initiative, the security team is investing more in the security release process, working through existing findings, and expanding proactive vulnerability research and tooling. Alongside that work, we’re updating the Vulnerability Disclosure Program guidelines so that our time, and the time of security researchers, is focused on valid vulnerabilities with clear and significant impact.
For any in-scope asset excluding WordPress CoreCore Core is the set of software required to run WordPress. The Core Development Team builds WordPress. and GutenbergGutenberg The Gutenberg project is the new Editor Interface for WordPress. The editor improves the process and experience of creating new content, making writing rich content much simpler. It uses ‘blocks’ to add richness rather than shortcodes, custom HTML etc. https://wordpress.org/gutenberg/, issues requiring a role that can only be granted by an administrator will generally no longer be eligible unless they demonstrate a high-severity escalation and security impact. This includes roles like Contributor. The ability for one authenticated role to perform an action normally available to another authenticated role will also generally not be sufficient on its own, unless it leads to a high impact escalation. WordPress Core and Gutenberg will, for now, continue to follow our existing eligibility guidelines. More examples can be found on our program policy page.
We encourage researchers to focus on vulnerabilities with a clear security impact, particularly high-severity issues that can be exploited without authentication or by low-privileged users such as Subscribers.
Responsible disclosure continues to be an important part of WordPress security and issues can be reported here. Combined with the work happening within the project to proactively identify and address vulnerabilities, focusing reports on higher-impact issues will help us spend more time on the findings that make WordPress and its ecosystem meaningfully safer.