Automattic

Security

Please note that if you run your own WordPress installation or are a WordPress developer and think you have found a security vulnerability in the open source WordPress software, here is how to report an issue.

Although we strive to create the most secure products possible, we are not perfect.  If you happen to find a security vulnerability in one of our services, we would appreciate letting us know and allowing us to respond before disclosing the issue publicly.   We take security seriously, and we will try to review and reply to every legitimate security report personally within 24 hours. Other reports submitted will not be replied to.

— Barry

For responsible disclosure of security issues and to be eligible for our bug bounty program, please submit your report via the HackerOne portal.