Bug Bounty Programs Compared: Wordfence, Patchstack, Bugcrowd and Immunefi

PC Drama
7 views

Bug bounty programs pay security researchers to find vulnerabilities and report them to the people who can fix them, and four programs cover most of the distance between a WordPress plugin and a Solidity contract. The table sets them side by side: what each one wants you to hunt, what it pays at the top, and the rule most likely to sink an otherwise good report.

ProgramResearch focusTop rewardRule that decides eligibility
Wordfence IntelligenceWordPress plugins and themes, free and premium$31,200 for standard researchers, $32,760 at the 1337 tierScope depends on the vulnerability and your researcher tier; some high-threat findings qualify at 1,000+ active installs
PatchstackWordPress plugins, themes and core$33,000 per zero-day, plus a $5,300 monthly top-five poolPayout scales with active installs and the privilege the exploit needs
Elementor on BugcrowdElementor security concerns other than its WordPress pluginsSet in the engagement brief, not published outside itPlugin issues go to Patchstack instead
OpenZeppelin on ImmunefiOpenZeppelin Contracts, the Solidity library$25,000 for a critical findingProof of concept required, KYC before payout, local forks only

Which Bug Bounty Program Fits Your Finding?

Route the report by what you found, and let the payout ceiling break ties. A bug filed with the wrong program usually ends in a polite closure and a lost week, and two of these four programs point part of their own scope at each other.

You foundSend it toWhy
A flaw in a WordPress plugin or theme with 1,000+ installsWordfence or PatchstackBoth pay for this class; compare tiers and install bands before you file
A flaw in WordPress corePatchstackIts top payout band covers core alongside 15M+ install components
A flaw in an Elementor WordPress pluginPatchstackElementor's reporting page sends plugin issues there
Any other Elementor security issueBugcrowdElementor lists Bugcrowd for everything outside its plugins
A bug in OpenZeppelin ContractsImmunefiThe only program in this set that covers Solidity

Wordfence Intelligence: Tiers and Scope

Close-up of a laptop keyboard edge lit by a cyan rim light, with a blurred code editor on the screen behind it
Plugin source on a laptop screen, the raw material of every Wordfence report.

Wordfence runs its bounty through Wordfence Intelligence, its WordPress vulnerability database, and the program covers free and premium plugins and themes alike. Rewards reach $31,200 for standard researchers and $32,760 for researchers in its 1337 tier, which opens every plugin and theme with at least 1,000 active installations.

For everyone below that tier, scope depends on the vulnerability class and your researcher standing, so a high-threat bug can qualify on a plugin that a low-severity one cannot. Wordfence publishes a reward estimator for a specific finding, and it is worth running yours through it before you plan the vacation, because the headline figure belongs to the rarest pairing of severity, install base and tier.

Patchstack: Payouts Scale With Install Count

Nine pairs of glowing amber and clear glass bars rising from left to right over a navy grid floor
Nine pairs of bars for Patchstack's nine install bands, the unauthenticated payout always the taller twin.

Patchstack pays per zero-day on a grid of two variables: how many sites run the vulnerable component, and whether the attacker needs a subscriber account or no account at all. The top cell, $33,000, is an unauthenticated flaw in WordPress core or in a component with 15 million or more installs, while a subscriber-level flaw in a plugin with 1,000 installs pays $125, a paid first lesson in how coordinated disclosure works.

Patchstack also runs a monthly leaderboard that splits $5,300 among its five most productive researchers, from $2,000 for first place down to $500 for fifth. A valid report earns its grid payout and a shot at the ranking, but it guarantees neither the maximum cell nor a place among the five.

Patchstack Zero-Day Payouts by Active Installs
Active installsSubscriber-level flawUnauthenticated flaw
15M+ or WordPress core$16,500$33,000
5M+$7,200$14,400
1M+$3,600$7,200
500K+$2,450$4,900
100K+$1,300$2,600
50K+$700$1,400
10K+$300$600
5K+$200$400
1K+$125$250

Monthly top-five pool: $2,000, $1,400, $800, $600 and $500, for $5,300 in total.

Elementor on Bugcrowd: Read the Brief First

Elementor splits its reports across two platforms. Its reporting page sends WordPress plugin issues to Patchstack and all other security concerns to its Bugcrowd program. We could not confirm Bugcrowd's current payout range or asset list from outside the engagement, so treat the program brief as the contract: it names the assets in scope, the testing you may run against them, and what earns a reward.

OpenZeppelin on Immunefi: Smart Contracts Only

Isometric chain of violet glass cubes with a branch feeding copies of three cubes into a lit glass sandbox tray
A chain copied into a sealed tray, which is what a local fork does: break it there and nothing live ever notices.

OpenZeppelin Contracts is the widely used Solidity library behind a long list of tokens and governance contracts, and its Immunefi program is the one entry here with nothing to do with web applications. Critical findings pay up to $25,000, every report needs a proof of concept, and OpenZeppelin asks for an invoice and a KYC screen before it pays out in ETH or USDC against a USD-denominated reward.

Testing on mainnet or a public testnet is prohibited. All of it happens on a local fork of either chain, which keeps your exploit proof from becoming somebody else's incident report.

OpenZeppelin on Immunefi: Rewards by Severity
SeverityMaximum rewardProof of concept
Critical$25,000Required
High$5,000Required
Medium$2,500Required
Low$1,000Required
  • Payouts are denominated in USD and paid in ETH or USDC.
  • An invoice and a KYC screen come before any reward.
  • Testing against pricing oracles or third-party contracts is out of bounds, as is automated testing that generates significant traffic.

Where Offensive Skill Goes to Defend

Top-down view of a dark grid desk holding an open notebook with a hand-drawn flowchart, a brass padlock, a laptop, a pen and a cup of coffee
A flowchart, a closed padlock and a cup of coffee, the usual kit for a report written to be fixed.

Every program above pays for the skill set an intruder uses: reading code for the flaw its author missed, then proving it with a working exploit. What changes is where the proof goes. A bounty report lands with the maintainer, the maintainer ships a patch, and the finding becomes a published advisory with your name on it instead of a line in somebody's breach notification.

"I was trying to create a mechanism for hackers to one, stay out of jail, and two, help people become more secure."

Katie Moussouris Founder and CEO, Luta Security, on why she helped create bug bounties, as quoted in CSO Online

That is one answer to the question we left open in our look at cyber threats to the energy and utilities sector, where CISA called the intruders unsophisticated and we asked how someone with that kind of skill gets pulled toward defense. Legal cover, public credit and a five-figure ceiling make a better recruiting pitch than any label. If WordPress plugins are your way in, our guide to preparing and protecting WordPress sites shows what the defenders on the receiving end of your report are working with.

Frequently Asked Questions
Which bug bounty program pays the most for a WordPress vulnerability?
Patchstack advertises the highest single payout in this set, up to $33,000 for an unauthenticated zero-day in WordPress core or a component with 15 million or more installs. Wordfence tops out at $31,200 for standard researchers and $32,760 in its 1337 tier.
Where do I report an Elementor vulnerability?
WordPress plugin issues go to Patchstack. Every other Elementor security concern goes to Elementor's Bugcrowd program, whose brief lists the assets in scope.
Does a valid report always earn the maximum reward?
No. Each program prices a finding by severity and scope, and Patchstack also weighs active installs and the privilege the exploit needs, so the headline figures belong to the rarest combinations of all three.
Why does OpenZeppelin require testing on a local fork?
Its Immunefi rules prohibit testing on mainnet or public testnets. A local fork copies chain state to your own machine, so an exploit proof runs without touching live contracts or anyone's funds.

About Bug Bounty Programs

Each program is run by the vendor or platform that publishes it, and terms change; the program page on the day you file is the version that counts.

Sources: Wordfence Intelligence, Patchstack, Elementor, Immunefi, CSO Online

Related Articles