Report a security problem privately. Please do not open a public issue or post in a support forum, and do not publish a proof of concept anywhere.
What to include
- the plugin and its version, and whether it is the free plugin or a paid add-on;
- your PHP and WordPress versions, and the hosting set-up if it matters;
- what an attacker gains, and what access they need first;
- the smallest reproduction you have.
What happens next
- We confirm that the report arrived.
- We tell you whether it reproduces, and how severe we judge it.
- We fix it, or explain in writing why the behaviour is intended. A real finding is fixed together with a regression test that fails without the fix.
- We credit you in the changelog, if you want.
Scope
Findings that need an attacker to already hold the manage_options capability are out of scope: a site administrator can already install arbitrary code. Problems in a third-party storage provider’s own service belong to that provider.
Only the most recent release of each plugin receives security fixes.