Earn cash bounties by hunting for vulnerabilities in WordPress software
Time to squash some security bugs! Successfully report a vulnerability to sign up to our bounty platform. Read the rules.
Zeroday payouts up to $33,000
Receive generous payouts for reporting high-impact vulnerabilities.
Rewards
| Installs | Subs | Unauth |
|---|---|---|
| 15M+/Core | $16,500 | 🔥$33,000 |
| 5M+ | $7,200 | $14,400 |
| 1M+ | $3,600 | $7,200 |
| 500K+ | $2,450 | $4,900 |
| 100K+ | $1,300 | $2,600 |
| 50K+ | $700 | $1,400 |
| 10K+ | $300 | $600 |
| 5K+ | $200 | $400 |
| 1K+ | $125 | $250 |
Monthly TOP20 prize pool $8,850
Guaranteed in monthly payouts to TOP20 + one lucky ethical hacker
Rewards
| 🥇 1st | $2,000 | |
| 🥈 2nd | $1,400 | |
| 🥉 3rd | $800 | |
| 4th | $600 | |
| 5th | $500 | |
| 6-10th | $400 | |
| 11-15th | $200 | |
| 16-19th | $100 | |
| 20th | $50 | |
| Random pick | $50 | |
| Random pick outside TOP20 | $50 |
Level up to unlock rewards $16,887
Earn extra rewards as you accumulate XP and level up.
Rewards
| Lvl 12 | $5,000 |
| Lvl 11 | $3,500 |
| Lvl 10 | $2,500 |
| Lvl 9 | $1,700 |
| Lvl 8 | $1,337 |
| Lvl 7 | $1,000 |
| Lvl 6 | $700 |
| Lvl 5 | $500 |
| Lvl 4 | $300 |
| Lvl 3 | $200 |
| Lvl 2 | $100 |
| Lvl 1 | $50 |
How to start your researcher profile?
1
Join the Alliance Discord (opens in new tab)↗ and read the submissions and payout terms
2
Report a vulnerability in WordPress (plugins with a VDP earn extra XP)
3
Once verified, the CVE is published in your name and you receive an invite.
4
Compete for monthly bounties, 0day payouts or earn by leveling up.
What the FAQ
Patchstack currently supports two forms of payouts:
- Paypal. Patchstack covers all payout fees, so you receive the full amount exactly as promised.
- Cryptocurrency payments (Bitcoin or Ethereum). Payouts are processed using the exchange rate available at the time of transaction. By choosing this payout method, you acknowledge and accept all associated risks.
XP points are calculated by combining parameters like CVSS score, active installation count, and prerequisites needed to carry out an attack. No points are given if the reported component has less than 500 active installs or requires an admin/super-admin role as a prerequisite.
Indeed, Patchstack is paying bounties for vulnerabilities even if the software vendors have no means to fund it. We finance the bounty program from our core business to give back to the community.
Everyone can join Patchstack's Bug Bounty program as long as they are committed to making the WordPress ecosystem safer. By submitting at least one valid vulnerability report that meets Patchstack's Bug Bounty program vulnerability report submission requirements, you become a member of Patchstack's Bug Bounty program.