Wordfence Bug Bounty Program Logged 1,288 Submissions in April 2026
Wordfence's monthly report shows its bug bounty program processed nearly 1,300 vulnerability submissions in April, as researchers continue to help harden the WordPress ecosystem.
All posts in this stream, newest first.
Wordfence's monthly report shows its bug bounty program processed nearly 1,300 vulnerability submissions in April, as researchers continue to help harden the WordPress ecosystem.
The padlock looks the same no matter which certificate sits behind it. Here is what DV, OV, and EV actually verify, and why automated free certificates are the right call for nearly every WordPress site.
XSS shows up in plugin vulnerability disclosures more than any other bug class. Here's what stored and reflected XSS actually do, why an admin's browser is the real prize, and how proper escaping closes the door.
Not all bot traffic is bad, and not all human traffic is safe. Here is how to read your logs, tell the players apart, and respond with the right level of force instead of a blanket ban.
Your WordPress login can be compromised without a single flaw in your site, just a password you reused somewhere else. Here is how the attack works, how to spot it, and why two-factor authentication shuts the whole class down.
The word 'managed' gets stamped on everything from bare VPS resellers to genuine full-stack platforms. Here is the checklist that tells you which one you are actually paying for.
A plain-language look at how SQL injection actually works, why WordPress core rarely causes it, and the layered defenses that keep a real attack from becoming a real breach.
The OWASP Top 10 is written for web applications in general. Here is what each risk actually looks like on a WordPress site, and the one fix that matters most for each.
Decoy fields, fake endpoints, and canary tokens turn an attacker's reconnaissance into your alert, often before they ever get close to real data.
Not all second factors are created equal. Here is how SMS, authenticator apps, and passkeys actually hold up against phishing and SIM swaps, and how to get a reluctant team to turn any of them on.