WordPress 6.5 Beta Bug Bounty: Double Rewards for New Core Security Bugs

WordPress 6.5 Beta 1 launched on February 13, 2024. This release marks the first major WordPress version of 2024. With the beta launch, the WordPress Security Team invites security researchers to hunt for security issues in new code. The bounty period runs from Beta 1 to the final release candidate. Valid submissions earn double bounties.

A New Year and a New Major Release

The start of a new year brings fresh energy to the WordPress project. WordPress 6.5 is almost ready. Beta 1 kicks off the testing phase. Security researchers play a key role during this phase. Their work helps catch problems before the final release. Therefore, the Security Team offers double bounties for qualifying reports.

Focus on New Code

The double bounty applies to security issues in new code. Reports must target code introduced between Beta 1 and the final release candidate. Existing vulnerabilities do not qualify. This focus helps the team find and fix security bugs before they reach millions of websites. For example, a researcher who finds a new vulnerability can earn twice the normal reward.

Editor Improvements in WordPress 6.5

WordPress 6.5 brings several new features and improvements. The Editor will receive notable upgrades, since the Editor is where most content creation happens. These changes aim to improve the editing experience. However, new code can introduce new security risks. Consequently, security researchers should pay close attention to these areas.

Release Schedule

The full release schedule offers more details. The timeline runs from Beta 1 through the final release candidate. Typically, several weeks separate these milestones. This window gives researchers time to test new code and report issues. The schedule helps everyone track progress and plan testing efforts.

How to Report Security Issues

The WordPress Security Team accepts security issues through the HackerOne program. The program policy lists general eligibility criteria. Researchers must follow those criteria. Reports that highlight issues in new code will be eligible for double bounties. As a reminder, the double bounty applies only to new code in the beta and release candidate period.

Earn More and Secure WordPress

WordPress 6.5 Beta 1 opens a valuable window for security research. New code needs careful review. Double bounties reward that effort. Security researchers can help make WordPress 6.5 safer for everyone. The final release will benefit from early findings. More details appear in the full release schedule and the HackerOne program policy.

Mehraz Morshed
Mehraz Morshed

Mehraz Morshed works part-time as a WordPress content writer for DaisyWP. He writes articles about WordPress and covers WordPress community events for DaisyWP.

He has a Bachelor of Science in Computer Science and Engineering from Patuakhali Science and Technology University. He also has a Master's in Japanese Studies from the University of Dhaka.

Mehraz is actively involved in various WordPress activities in Bangladesh, including development, education, and community building.

Articles: 2