Wordfence Bug Bounty Program Surpasses 1000 Submissions in May 2026
Wordfence's May 2026 Bug Bounty Program report highlights a significant influx of 1095 vulnerability submissions for WordPress plugins and themes, underscoring the ongoing need for robust security research in the WordPress ecosystem.

The Wordfence Bug Bounty Program has reported a substantial volume of security research activity for May 2026, detailing 1095 vulnerability submissions from a growing community of security researchers. This initiative aims to proactively identify and responsibly disclose vulnerabilities within the vast WordPress plugin and theme ecosystem, thereby enhancing the security posture for millions of websites worldwide.
The Wordfence Threat Intelligence team meticulously reviews, triages, and processes each submission. Validated vulnerabilities are then responsibly disclosed to the respective vendors, often facilitated through the free Wordfence Vulnerability Management Portal. This portal serves as a centralized platform for vendors to manage disclosed issues, streamlining the patching process. Where applicable, these vulnerabilities are also protected by the Wordfence Firewall, offering immediate protection to users of the Wordfence security product.
This program's core mission is to foster collaboration between security researchers and vendors. By incentivizing the discovery and responsible disclosure of flaws before they are exploited by malicious actors, Wordfence accelerates patch adoption and provides crucial early protection. The program's success is measured not only by the number of submissions but also by the efficiency with which vulnerability intelligence is disseminated and acted upon within the WordPress community.
In May 2026, the program saw a total of 1095 submissions, a 15.0% decrease from the previous month, with 293 active researchers contributing. Despite the slight dip in submissions, the program identified 35 "High Threat" vulnerabilities and 38 "Common & Dangerous" vulnerabilities, indicating a continued focus on critical security issues. The Wordfence Firewall saw the release of 6 new rules, a 100% increase from the prior month, directly stemming from these research efforts.
Financial incentives remain a key component of the program's success. In May, a total of $34,454 in bounties was awarded, with an average bounty of $231.23 per validated submission. The highest single bounty paid was $6,436, awarded for an unauthenticated privilege escalation vulnerability in Kirki version 6.0.0 to 6.0.6, which affects over 500,000 active installations.
Other notable high-value findings included an unauthenticated arbitrary file deletion vulnerability in Avada (Fusion) Builder (<= 3.15.3), which garnered a $3,600 bounty and impacts nearly a million sites, and an authenticated privilege escalation flaw in AI Engine (3.4.9) that earned $1,931 and affects 100,000 installations.
The Wordfence Bug Bounty Program emphasizes transparency, accuracy, and urgency in its operations. It actively encourages skilled researchers to participate, offering prompt payments and a clear, standardized workflow from validation to patch verification and firewall coverage. This commitment ensures that research findings translate into tangible security improvements for the WordPress ecosystem.
By engaging a broad spectrum of the security community, Wordfence aims to be the most comprehensive and highest-quality vulnerability program for WordPress. The monthly reports, like this May 2026 summary, provide valuable insights into emerging threats, researcher contributions, and the overall health of WordPress security, empowering site owners, developers, and hosting providers to stay ahead of potential risks.