Vulnerability Disclosure Policy

At AyeCode Ltd, we take the security of our software and our users seriously. We value the work of independent security researchers and encourage the responsible disclosure of potential vulnerabilities in our products.

To provide researchers with a consistent process for reporting vulnerabilities and, where eligible, receiving rewards, we participate in the Wordfence Bug Bounty Program.

Scope

This policy applies to WordPress plugins and themes developed and maintained by AyeCode Ltd, including our official product families and add-ons, such as:

  • GeoDirectory
  • UsersWP
  • GetPaid
  • BlockStrap
  • Official AyeCode add-ons and extensions

Eligibility for a bounty depends on the current scope, vulnerability type, active installation requirements, researcher tier, and other rules of the Wordfence Bug Bounty Program.

Participation in this policy does not mean that every vulnerability or AyeCode product is necessarily eligible for a monetary reward.

Reporting a Vulnerability

If you discover a potential security vulnerability in one of our WordPress plugins or themes, please submit it directly through the Wordfence Vulnerability Submission Form:

Submit a vulnerability to Wordfence

For vulnerabilities being submitted through the Wordfence Bug Bounty Program, please do not submit the same vulnerability separately to AyeCode or another vulnerability disclosure program. Wordfence requires qualifying submissions to be handled through its coordinated disclosure process.

Wordfence Bug Bounty Program

Wordfence coordinates the submission, triage, validation, CVE assignment where applicable, responsible disclosure process, and bounty payment for eligible vulnerabilities submitted through its program.

Researchers participating in the program must comply with the current Wordfence Bug Bounty Program rules and Wordfence Vulnerability Disclosure Policy.

Bounty eligibility and reward amounts are determined by Wordfence according to its current program terms and are not determined or guaranteed by AyeCode Ltd.

Responsible Disclosure

We ask researchers to:

  • Follow the Wordfence Bug Bounty Program rules and responsible disclosure requirements.
  • Avoid accessing, modifying, deleting, or retaining data belonging to other users.
  • Avoid actions that could degrade, interrupt, or damage services or systems.
  • Test only to the extent necessary to demonstrate the existence and impact of a vulnerability.
  • Keep vulnerability details confidential until disclosure is coordinated by Wordfence.
  • Provide sufficient technical information and a reproducible proof of concept to allow the issue to be investigated.

When Wordfence notifies us of a validated vulnerability, we will:

  • Investigate the reported issue as quickly as reasonably possible.
  • Work to develop and release an appropriate fix for confirmed vulnerabilities.
  • Cooperate with Wordfence throughout the coordinated disclosure process.
  • Where appropriate, credit the researcher following disclosure.

Out of Scope

Unless specifically accepted under the current Wordfence Bug Bounty Program rules, the following are outside the scope of this policy:

  • Social engineering, phishing, or attacks against AyeCode employees, contractors, customers, or users.
  • Denial-of-Service (DoS), Distributed Denial-of-Service (DDoS), or other availability attacks.
  • Brute-force attacks or excessive automated traffic.
  • Vulnerabilities requiring physical access to a device or system.
  • Vulnerabilities in third-party software, services, hosting providers, or infrastructure that AyeCode does not control.
  • Security issues that exist solely because of an insecure or unsupported third-party configuration.
  • Reports without a demonstrable security impact.
  • Issues that Wordfence classifies as out of scope or as common false positives.

The Wordfence program maintains its own detailed and authoritative eligibility criteria. Researchers should review the current Wordfence Bug Bounty Program scope and rules before testing or submitting a vulnerability.

AyeCode Websites and Hosted Services

The Wordfence Bug Bounty Program primarily covers qualifying vulnerabilities in WordPress plugins and themes. Vulnerabilities affecting AyeCode-operated websites, account systems, APIs, hosted services, or other infrastructure may not be eligible under the Wordfence Bug Bounty Program.

Security issues affecting those systems should be reported separately to [email protected]

Please do not send a WordPress plugin or theme vulnerability to this address if you intend to submit it through the Wordfence Bug Bounty Program.

Thank You

We appreciate the work of the security research community and its contribution to making AyeCode products and the wider WordPress ecosystem safer.