Bug Bounty
2026
- 09-26: GeoDirectory Stored XSS via a Text-type Custom Field - Wordfence bug bounty, $48
- 09-26: Better Messages Unauthenticated Information Exposure via a Spoofed AI Bot Identity - Wordfence bug bounty, $34
- 09-26: WCFM Marketplace Unauthenticated SQL Injection via Checkout Distance Shipping - Wordfence bug bounty, $134
- 09-26: Better Messages Unauthenticated Reflected XSS via the Live Chat Builder Preview - Wordfence bug bounty, $23
- 09-26: Job Postings Stored XSS via the position_button Field - Wordfence bug bounty, $5
- 09-26: WP Photo Album Plus Unauthenticated Stored XSS via Error Log Injection - Wordfence bug bounty, $80
- 08-26: MetForm Stored XSS via the mf_form_id Widget Setting - Wordfence bug bounty, $72
- 08-26: UsersWP Badge Widget Stored XSS via Variable Substitution - Wordfence bug bounty, $72
- 07-26: Essential Addons for Elementor Global Reading Progress Stored XSS - Wordfence bug bounty, $96
- 07-26: Essential Addons for Elementor Email Header Injection to Account Takeover - Wordfence bug bounty, $859
- 07-26: Contact Form Entries Arbitrary File Copy to File Read - Wordfence bug bounty, $100
- 06-26: Survey Maker Time-Based Answer Stored XSS - Wordfence bug bounty, $0
- 06-26: Photo Gallery Compact Album Second-Order Blind SQL Injection - Wordfence bug bounty, $60
- 06-26: ProfileGrid Stored XSS via Private Messages - Wordfence bug bounty, $37
- 05-26: ProfileGrid rid SQL Injection - Wordfence bug bounty, $31
- 04-26: Elementor REST API Stored XSS - Wordfence bug bounty, $288
2025