WordPress has tightened the rules for what it accepts through its HackerOne bug bounty program, part of the Core Security Initiative it announced yesterday to keep pace with a surge in AI-assisted vulnerability reports.
What changed
Automattic security engineer Ehtisham Siddiqui published the updated scope on the Making WordPress Secure blog. For every in-scope plugin and product except WordPress Core and Gutenberg, vulnerabilities that require a role an administrator has to grant, such as Contributor, will generally no longer qualify unless they demonstrate a high-severity escalation with clear security impact. Reports where one logged-in role can do something normally reserved for another role also won’t qualify on their own unless they lead to a serious escalation.
Siddiqui wrote the change is about making sure the security team’s time, and researchers’ time, stays focused on “valid vulnerabilities with clear and significant impact” rather than low-severity edge cases. WordPress Core and Gutenberg keep their existing eligibility rules for now.
What this means for your site
This doesn’t change how you should maintain your site. Keep automatic updates on and apply security releases promptly. What it does mean is that WordPress’s security team is deliberately triaging harder, so the vulnerabilities that do get disclosed and patched going forward should more consistently be the ones that matter, unauthenticated flaws and serious privilege escalations rather than minor role-based edge cases.
End of article