WordPress 6.4 Beta has arrived. The WordPress Security Team wants to find potential security issues before the final WordPress release. Consequently, the team doubles the bounty for any new vulnerability in Core that researchers report after Beta 1 and before the final release candidate (RC).
Why the Bonus Matters
The Security Team aims to catch security bugs before they land in a final release. Like earlier efforts, the team encourages researchers to focus more attention on new code in beta releases. Therefore, new Core vulnerabilities in that window earn double rewards. For example, a bug that normally earns $600 becomes $1200 under this bonus.
Timeline for 6.4 Beta and RC
Beta 1 arrives today. The official release schedule lists dates for each WordPress 6.4 Beta and RC release. Typically, about one month separates the first beta and the last release candidate. During that window, researchers can report new security bugs.
How Researchers Report Security Issues
The WordPress Security Team accepts security issues through the HackerOne program. The program policy lists general eligibility criteria. Researchers must follow those criteria. Reports outside policy do not qualify.
Do Existing Vulnerabilities Qualify?
No. The bonus focuses on catching security bugs before they enter a final release. Therefore, only vulnerabilities in new code qualify. Existing vulnerabilities do not qualify, even during the beta period.
Earn More and Secure WordPress
This bug bounty gives researchers a chance to help WordPress security and earn more. New Core vulnerabilities in the WordPress 6.4 Beta and RC period can bring double rewards. The final release benefits from early fixes. The official schedule and HackerOne policy provide more details.






