Report a security problem privately. Please do not open a public issue or post in a support forum, and do not publish a proof of concept anywhere.

What to include

  • the plugin and its version, and whether it is the free plugin or a paid add-on;
  • your PHP and WordPress versions, and the hosting set-up if it matters;
  • what an attacker gains, and what access they need first;
  • the smallest reproduction you have.

What happens next

  • We confirm that the report arrived.
  • We tell you whether it reproduces, and how severe we judge it.
  • We fix it, or explain in writing why the behaviour is intended. A real finding is fixed together with a regression test that fails without the fix.
  • We credit you in the changelog, if you want.

Scope

Findings that need an attacker to already hold the manage_options capability are out of scope: a site administrator can already install arbitrary code. Problems in a third-party storage provider’s own service belong to that provider.

Only the most recent release of each plugin receives security fixes.