WordPress 6.6 is the next major WordPress release, and the first beta was released on June 4, 2024.
As WordPress 6.6 gets closer to its beta release, security researchers have an opportunity to help find and report new security bugs before the final release.
Double Rewards for WordPress 6.6 Security Bugs
Security researchers who find a qualifying security issue after WordPress 6.6 Beta 1 is released and before the final Release Candidate (RC) may be eligible for double the usual reward.
The security issue must be related to new code introduced in WordPress 6.6 to qualify for the double reward.
This gives security researchers an opportunity to test the new code and help identify potential security problems before WordPress 6.6 reaches its final release.
Check the WordPress 6.6 Release Schedule
WordPress has published a schedule for the WordPress 6.6 Beta and RC releases. Checking the schedule can help security researchers know when the beta and RC testing periods begin and end.
How to Report a WordPress 6.6 Security Bug
If you find a potential security vulnerability in WordPress 6.6, you can report it through HackerOne.
Before submitting a report, make sure to read the WordPress security program policy. It explains the program rules and requirements for security reports.
By testing the new WordPress 6.6 code and reporting valid security issues, researchers can help make the upcoming release safer for WordPress users.






