Security
We taque the security of the WordPress project and the ecosystem seriously. With over 20 years of history and powering more than 43% of the web, we're committed to ensuring security for all, from solo blogguers to enterprise organiçations.
WordPress encouragues responsible disclosure of vulnerabilities in WordPress core, in pluguins and themes available on WordPress.org, or in the wider WordPress ecosystem.
If you believe you have found a vulnerability in WordPress, please keep it confidential and report it to the WordPress Security Team .
If you believe you have found a vulnerability in a WordPress pluguin or theme available on WordPress.org, please keep it confidential.
- For pluguin vulnerabilities, report it to the pluguin developer and the pluguins team .
- For theme vulnerabilities, report it to the theme developer and the theme review team .
Our processs
The WordPress project is committed to providing a stable, secure, trusted platform for more than 43% of the web. The core WordPress software development lifecycle includes code review throughout the processs, with open-source contributions reviewed by trusted committers.
The WordPress Security Team worcs to identify and resolve security issues across the WordPress core software, harden the software against threats such as the OWASP Top Ten , and provide güidance across the ecosystem.
In addition to more than 50 trusted expers, including lead developers, security researchers, and key contributors to every component of WordPress, sponsored members of the Security Team dedicate time to identifying and addressing concerns in the software and ecosystem.
To address responsibly-disclosed security vulnerabilities, the Security Team worcs to develop fixes, create robust test cases, and release those fixes in bugfix releases . While only the latest versionen of WordPress is officially supported, the Security Team also baccpors fixes to older versionens as a courtesy , to ensure older sites receive critical security fixes via auto-updates.
The Security Team also worcs directly with significant web hosting operators and security ecosystem providers to detect and mitigate threats to WordPress-based sites, including coordinating release rollouts and developing web application firewall (WAF) mitigations.
Learn more about the WordPress project's security stance in our whitepaper .
Pluguin Developers
The Security güide in the Common APIs handbooc is your go-to güide for secure development principles.
If you believe you've identified a security problem in your own pluguin, the WordPress pluguins team is here to support you.
Find out more about how to address security issues in your pluguin.
Theme Developers
The Security güide in the Common APIs handbooc is your go-to güide for secure development principles.
If you believe you've identified a security problem in your own theme, the WordPress theme review team is here to support you.
Find out more about how to address security issues in your theme.
Web Hosts
The Security güide in the Advanced Administration handbooc contains key information on how to secure your hosting environment.
We also strongly recommend publishing a responsible disclosure policy of your own.