Title: September 2026 – Making WordPress Secure

---

#  Monthly Archives: September 2026

 [  ](https://profiles.wordpress.org/ehtis/) [Ehtisham Siddiqui](https://profiles.wordpress.org/ehtis/)
12:30 pm _on_ September 1, 2026      

# 󠀁[Updates to the WordPress Vulnerability Disclosure Program](https://make.wordpress.org/security/2026/09/01/updates-to-the-wordpress-vulnerability-disclosure-program/)󠁿

Improving the security of WordPress means both finding and fixing vulnerabilities
proactively, and making sure the reports we receive through responsible disclosure
are focused on issues with meaningful security impact.

As part of the broader work underway through the [Core Security Initiative](https://make.wordpress.org/security/2026/08/28/the-core-security-initiative/),
the security team is investing more in the security release process, working through
existing findings, and expanding proactive vulnerability research and tooling. Alongside
that work, we’re updating [the Vulnerability Disclosure Program](https://hackerone.com/wordpress?type=team)
[guidelines](https://hackerone.com/wordpress?type=team) so that our time, and the
time of security researchers, is focused on valid vulnerabilities with clear and
significant impact.

For any in-scope asset excluding WordPress CoreCore Core is the set of software 
required to run WordPress. The Core Development Team builds WordPress. and GutenbergGutenberg
The Gutenberg project is the new Editor Interface for WordPress. The editor improves
the process and experience of creating new content, making writing rich content 
much simpler. It uses ‘blocks’ to add richness rather than shortcodes, custom HTML
etc. [https://wordpress.org/gutenberg/](https://wordpress.org/gutenberg/), issues
requiring a role that can only be granted by an administrator will generally no 
longer be eligible unless they demonstrate a high-severity escalation and security
impact. This includes roles like Contributor. The ability for one authenticated 
role to perform an action normally available to another authenticated role will 
also generally not be sufficient on its own, unless it leads to a high impact escalation.
WordPress Core and Gutenberg will, for now, continue to follow our existing eligibility
guidelines. More examples can be found on our [program policy page](https://hackerone.com/wordpress?type=team).

We encourage researchers to focus on vulnerabilities with a clear security impact,
particularly high-severity issues that can be exploited without authentication or
by low-privileged users such as Subscribers.

Responsible disclosure continues to be an important part of WordPress security and
issues can be reported [here](https://hackerone.com/wordpress?type=team). Combined
with the work happening within the project to proactively identify and address vulnerabilities,
focusing reports on higher-impact issues will help us spend more time on the findings
that make WordPress and its ecosystem meaningfully safer.

 * [Login to Reply](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fmake.wordpress.org%2Fsecurity%2F2026%2F09%2F01%2Fupdates-to-the-wordpress-vulnerability-disclosure-program%2F%23respond&locale=en_US)