WordPress
HackerOne live webgit_repoBug bounty program on HackerOne. Official listing: https://hackerone.com/wordpress. Scope and rules are controlled by the program — always verify against the official listing before testing.
Max bounty
$25K
Starts
2016-07-23
In-scope assets
9
Last updated
2026-09-02
In-scope assets
| Type | Asset | Detail |
|---|---|---|
| repo | wordpress/gutenberg | |
| web | *.wordcamp.org | |
| web | *.wordpress.net | |
| web | *.wordpress.org | |
| web | api.wordpress.org | |
| web | doaction.org | |
| web | mercantile.wordpress.org | |
| web | planet.wordpress.org | |
| web | wordpressfoundation.org |
Watching WordPress? BountyHunt monitors every in-scope repo and tells you the moment a commit, release, or scope change lands — in the app, by webhook, or straight to your agent over MCP.
Track this program