Submit a vulnerability to VMP™ Security
Help us keep the WordPress ecosystem secure
Before you submit: please check the VMP™ Security vulnerability database to see whether this vulnerability has already been reported. If you need a CVE identifier assigned, use the Request CVE form instead.
VMP™ Security vulnerability submission form
Thank you for choosing to submit a vulnerability to the VMP™ Security Intelligence Vulnerability Database. Our team thoroughly researches and documents reported vulnerabilities to help improve security across the WordPress ecosystem. All submissions are reviewed by our security team, and you will be contacted at the email address you provide.
Submission received
Reference number:
Our security team typically responds within 1–3 business days.
What happens next
Your report is stored securely and reviewed by the VMP™ Security threat-intelligence team. Confirmed findings are published to our public vulnerability database after responsible disclosure.
Need a CVE ID?
If you need a CVE identifier assigned for your finding, use our Request CVE form — we review CVE requests within 1–3 business days.
Browse the database
The VMP™ Security Intelligence WordPress vulnerability database is free for everyone. Explore all published vulnerabilities affecting WordPress core, plugins, and themes.