Meta tags:
description= WPScan s Vulnerability Disclosure Policy;
Headings (most frequently used words):
disclosure, wpscan, vulnerability, policy, scope, initial, contact, deadlines, escalation, to, marketplace, vulnerabilities, about, for, developers, other,
Text of the page (most frequently used words):
the (40), wpscan (17), and (13), that (10), vendor (9), contact (8), will (8), with (7), for (7), #disclosure (7), #vulnerability (7), policy (6), vulnerabilities (6), wordpress (5), their (5), may (5), issue (5), email (5), individual (5), organization (5), users (4), details (4), how (4), affected (4), not (4), marketplace (4), are (4), days (4), initial (4), security (4), this (4), protected (4), terms (3), other (3), cli (3), scanner (3), api (3), status (3), developers (3), pricing (3), works (3), submit (3), stats (3), themes (3), plugins (3), its (3), one (3), make (3), item (3), vendors (3), jetpack (2), privacy (2), notice (2), plugin (2), about (2), limited (2), has (2), been (2), deadline (2), being (2), exploited (2), respond (2), public (2), alert (2), website (2), after (2), business (2), second (2), patch (2), appropriate (2), using (2), used (2), flaw (2), responsible (2), manner (2), any (2), product (2), vulnerable (2), coordinator (2), coordinated (2), 2022 (2), get (2), started (2), login (2), web (2), 2021 (2), jan (2), work, endeavor, partnership, california, submission, service, news, our, disclose, remediated, issues, delay, own, discretion, provide, feasible, time, update, systems, proof, concept, articles, unpublished, least, week, counting, from, date, advisory, issued, along, mitigation, plan, order, allow, defensive, community, safeguard, user, responsive, unable, reasonable, argument, why, addressed, actively, believe, taking, these, steps, recognize, obligation, customers, appropriately, stating, findings, soon, decides, remove, unavailable, download, reached, still, fixed, new, versions, released, without, fixes, attempts, fix, fails, reply, additional, two, following, notification, phase, when, published, escalate, them, escalation, given, thirty, resolve, remedial, measure, extendable, cases, high, complexity, 120, hundred, twenty, first, deadlines, does, communication, within, three, official, different, method, than, earlier, publicly, available, timely, effort, made, suitable, contacts, formal, channels, stated, sending, relevant, regarding, reported, evaluate, coordinate, can, defined, weakness, application, core, extensions, could, triggered, threat, source, scope, hosts, distributes, same, created, maintains, must, deploy, take, remediation, action, reporter, identifies, notifies, interested, parts, finding, facilitates, response, process, case, better, understanding, define, throughout, avoid, ambiguity, they, explains, conducts, disclosures, extension, general, last, updated, july, 26th, wayback, machine, http, archive, org, 20221207172517, https, com, timestamps, capture, fail, success, 2023, dec, nov, sep, 2026, 110, captures,
Text of the page (random words):
wpscan vulnerability disclosure policy 110 captures 01 jan 2021 02 sep 2026 nov dec jan 07 2021 2022 2023 success fail about this capture timestamps the wayback machine http web archive org web 20221207172517 https wpscan com vulnerability disclosure policy wpscan how it works pricing vulnerabilities wordpress plugins themes stats submit vulnerabilities for developers status api details cli scanner contact login get started wpscan how it works pricing vulnerabilities wordpress plugins themes stats submit vulnerabilities for developers status api details cli scanner contact login get started wpscan vulnerability disclosure policy last updated july 26th 2022 this policy explains how the wpscan conducts vulnerability disclosures to extension vendors wpscan users jetpack users security vendors and the general public in a coordinated and responsible manner as for better understanding we will define terms that may be used throughout the policy to avoid ambiguity they are coordinator an individual or organization that facilitates the coordinated response process in this case it s wpscan reporter the individual or organization that identifies the vulnerability and notifies interested parts the vendor and or the coordinator with the finding vendor the individual or organization that created or maintains the product that is vulnerable and that must deploy a patch or take other remediation action marketplace the individual or organization that hosts and distributes the product that is vulnerable it may be the same individual or organization as the vendor scope wpscan will evaluate and coordinate the disclosure of any security flaw that can be defined as a weakness in a wordpress application core or its extensions and could be exploited or triggered by a threat source initial contact wpscan will alert the appropriate vendor of a security flaw in their affected item s in a responsible and timely manner the initial contact effort will be made using any suitable contacts or formal channels stated on the vendor s website or by sending an email to email protected email protected email protected and email protected with the relevant details regarding the reported issue if a vendor does not respond to wpscan s initial communication within three business days wpscan may make a second official contact using a different method than the one used earlier if publicly available deadlines vendors are given 30 thirty days to resolve the vulnerability with a security patch or other appropriate remedial measure this is extendable in cases of high complexity limited to 120 one hundred and twenty days after first contact escalation to marketplace when the affected item s are published in a marketplace wpscan will escalate the issue to them if the vendor fails to reply after an additional two business days following the second notification of the initial contact phase or new versions of the affected item s are being released without fixes attempts to fix the issue or the deadline has been reached and the issue is still not fixed disclosure wpscan may issue a public alert stating its findings as soon as the marketplace decides to remove the plugin or make it unavailable for download on their website a limited advisory may be issued by wpscan along with a mitigation plan in order to allow the defensive community to safeguard the user if a vendor is not responsive or unable to make a reasonable argument as to why the vulnerability has not been addressed by the deadline or if we notice it being actively exploited we believe that by taking these steps the vendor will recognize their obligation to their customers and respond appropriately wpscan will disclose remediated issues with a delay at its own discretion to provide affected users feasible time to update their systems proof of concept articles will be unpublished for at least one week counting from disclosure date wpscan vulnerabilities wordpress plugins themes our stats submit vulnerabilities about how it works pricing wordpress plugin news contact for developers status api details cli scanner other privacy terms of service submission terms disclosure policy privacy notice for california users in partnership with jetpack an endeavor work with us
|