Bug bounty programs pay security researchers to find vulnerabilities and report them to the people who can fix them, and four programs cover most of the distance between a WordPress plugin and a Solidity contract. The table sets them side by side: what each one wants you to hunt, what it pays at the top, and the rule most likely to sink an otherwise good report.
| Program | Research focus | Top reward | Rule that decides eligibility |
|---|---|---|---|
| Wordfence Intelligence | WordPress plugins and themes, free and premium | $31,200 for standard researchers, $32,760 at the 1337 tier | Scope depends on the vulnerability and your researcher tier; some high-threat findings qualify at 1,000+ active installs |
| Patchstack | WordPress plugins, themes and core | $33,000 per zero-day, plus a $5,300 monthly top-five pool | Payout scales with active installs and the privilege the exploit needs |
| Elementor on Bugcrowd | Elementor security concerns other than its WordPress plugins | Set in the engagement brief, not published outside it | Plugin issues go to Patchstack instead |
| OpenZeppelin on Immunefi | OpenZeppelin Contracts, the Solidity library | $25,000 for a critical finding | Proof of concept required, KYC before payout, local forks only |
Which Bug Bounty Program Fits Your Finding?
Route the report by what you found, and let the payout ceiling break ties. A bug filed with the wrong program usually ends in a polite closure and a lost week, and two of these four programs point part of their own scope at each other.
| You found | Send it to | Why |
|---|---|---|
| A flaw in a WordPress plugin or theme with 1,000+ installs | Wordfence or Patchstack | Both pay for this class; compare tiers and install bands before you file |
| A flaw in WordPress core | Patchstack | Its top payout band covers core alongside 15M+ install components |
| A flaw in an Elementor WordPress plugin | Patchstack | Elementor's reporting page sends plugin issues there |
| Any other Elementor security issue | Bugcrowd | Elementor lists Bugcrowd for everything outside its plugins |
| A bug in OpenZeppelin Contracts | Immunefi | The only program in this set that covers Solidity |
Wordfence Intelligence: Tiers and Scope
Wordfence runs its bounty through Wordfence Intelligence, its WordPress vulnerability database, and the program covers free and premium plugins and themes alike. Rewards reach $31,200 for standard researchers and $32,760 for researchers in its 1337 tier, which opens every plugin and theme with at least 1,000 active installations.
For everyone below that tier, scope depends on the vulnerability class and your researcher standing, so a high-threat bug can qualify on a plugin that a low-severity one cannot. Wordfence publishes a reward estimator for a specific finding, and it is worth running yours through it before you plan the vacation, because the headline figure belongs to the rarest pairing of severity, install base and tier.
Patchstack: Payouts Scale With Install Count
Patchstack pays per zero-day on a grid of two variables: how many sites run the vulnerable component, and whether the attacker needs a subscriber account or no account at all. The top cell, $33,000, is an unauthenticated flaw in WordPress core or in a component with 15 million or more installs, while a subscriber-level flaw in a plugin with 1,000 installs pays $125, a paid first lesson in how coordinated disclosure works.
Patchstack also runs a monthly leaderboard that splits $5,300 among its five most productive researchers, from $2,000 for first place down to $500 for fifth. A valid report earns its grid payout and a shot at the ranking, but it guarantees neither the maximum cell nor a place among the five.
Patchstack Zero-Day Payouts by Active Installs
| Active installs | Subscriber-level flaw | Unauthenticated flaw |
|---|---|---|
| 15M+ or WordPress core | $16,500 | $33,000 |
| 5M+ | $7,200 | $14,400 |
| 1M+ | $3,600 | $7,200 |
| 500K+ | $2,450 | $4,900 |
| 100K+ | $1,300 | $2,600 |
| 50K+ | $700 | $1,400 |
| 10K+ | $300 | $600 |
| 5K+ | $200 | $400 |
| 1K+ | $125 | $250 |
Monthly top-five pool: $2,000, $1,400, $800, $600 and $500, for $5,300 in total.
Elementor on Bugcrowd: Read the Brief First
Elementor splits its reports across two platforms. Its reporting page sends WordPress plugin issues to Patchstack and all other security concerns to its Bugcrowd program. We could not confirm Bugcrowd's current payout range or asset list from outside the engagement, so treat the program brief as the contract: it names the assets in scope, the testing you may run against them, and what earns a reward.
OpenZeppelin on Immunefi: Smart Contracts Only
OpenZeppelin Contracts is the widely used Solidity library behind a long list of tokens and governance contracts, and its Immunefi program is the one entry here with nothing to do with web applications. Critical findings pay up to $25,000, every report needs a proof of concept, and OpenZeppelin asks for an invoice and a KYC screen before it pays out in ETH or USDC against a USD-denominated reward.
Testing on mainnet or a public testnet is prohibited. All of it happens on a local fork of either chain, which keeps your exploit proof from becoming somebody else's incident report.
OpenZeppelin on Immunefi: Rewards by Severity
| Severity | Maximum reward | Proof of concept |
|---|---|---|
| Critical | $25,000 | Required |
| High | $5,000 | Required |
| Medium | $2,500 | Required |
| Low | $1,000 | Required |
- Payouts are denominated in USD and paid in ETH or USDC.
- An invoice and a KYC screen come before any reward.
- Testing against pricing oracles or third-party contracts is out of bounds, as is automated testing that generates significant traffic.
Where Offensive Skill Goes to Defend
Every program above pays for the skill set an intruder uses: reading code for the flaw its author missed, then proving it with a working exploit. What changes is where the proof goes. A bounty report lands with the maintainer, the maintainer ships a patch, and the finding becomes a published advisory with your name on it instead of a line in somebody's breach notification.
"I was trying to create a mechanism for hackers to one, stay out of jail, and two, help people become more secure."
Katie Moussouris Founder and CEO, Luta Security, on why she helped create bug bounties, as quoted in CSO Online
That is one answer to the question we left open in our look at cyber threats to the energy and utilities sector, where CISA called the intruders unsophisticated and we asked how someone with that kind of skill gets pulled toward defense. Legal cover, public credit and a five-figure ceiling make a better recruiting pitch than any label. If WordPress plugins are your way in, our guide to preparing and protecting WordPress sites shows what the defenders on the receiving end of your report are working with.
Frequently Asked Questions
- Which bug bounty program pays the most for a WordPress vulnerability?
- Patchstack advertises the highest single payout in this set, up to $33,000 for an unauthenticated zero-day in WordPress core or a component with 15 million or more installs. Wordfence tops out at $31,200 for standard researchers and $32,760 in its 1337 tier.
- Where do I report an Elementor vulnerability?
- WordPress plugin issues go to Patchstack. Every other Elementor security concern goes to Elementor's Bugcrowd program, whose brief lists the assets in scope.
- Does a valid report always earn the maximum reward?
- No. Each program prices a finding by severity and scope, and Patchstack also weighs active installs and the privilege the exploit needs, so the headline figures belong to the rarest combinations of all three.
- Why does OpenZeppelin require testing on a local fork?
- Its Immunefi rules prohibit testing on mainnet or public testnets. A local fork copies chain state to your own machine, so an exploit proof runs without touching live contracts or anyone's funds.
About Bug Bounty Programs
- Wordfence Intelligence Bug Bounty Program: tiers, scope and reward estimator
- Patchstack Bug Bounty: zero-day payouts and monthly leaderboard
- Elementor's bug bounty programs: where to report plugin and non-plugin issues
- OpenZeppelin on Immunefi: severity rewards, PoC and KYC rules
Each program is run by the vendor or platform that publishes it, and terms change; the program page on the day you file is the version that counts.
Sources: Wordfence Intelligence, Patchstack, Elementor, Immunefi, CSO Online