Submit a vulnerability to VMP™ Security

Help us keep the WordPress ecosystem secure

Before you submit: please check the VMP™ Security vulnerability database to see whether this vulnerability has already been reported. If you need a CVE identifier assigned, use the Request CVE form instead.

VMP™ Security vulnerability submission form

Thank you for choosing to submit a vulnerability to the VMP™ Security Intelligence Vulnerability Database. Our team thoroughly researches and documents reported vulnerabilities to help improve security across the WordPress ecosystem. All submissions are reviewed by our security team, and you will be contacted at the email address you provide.

Submission received

Reference number:
Our security team typically responds within 1–3 business days.

Browse the vulnerability database

What happens next

Your report is stored securely and reviewed by the VMP™ Security threat-intelligence team. Confirmed findings are published to our public vulnerability database after responsible disclosure.

Need a CVE ID?

If you need a CVE identifier assigned for your finding, use our Request CVE form — we review CVE requests within 1–3 business days.

Browse the database

The VMP™ Security Intelligence WordPress vulnerability database is free for everyone. Explore all published vulnerabilities affecting WordPress core, plugins, and themes.