The Wordfence Bug Bounty Program received 1,718 vulnerability submissions in March 2026 — a 59.4% increase over February — from 321 active security researchers, up 51.4% month-over-month.

Each submission goes through a standardised workflow: validation by the Wordfence Threat Intelligence team, coordination with the affected plugin or theme vendor, and patch verification. Confirmed vulnerabilities also generate new firewall rules to protect sites while a fix is developed. The monthly report does not break out a payout range or a validation rate for March, so it’s not possible to say what share of the 1,718 submissions were ultimately confirmed as genuine vulnerabilities.

Gloved hands inspect one amber glass vial among hundreds of labeled specimen vials arranged on a white lab table.

Wordfence Bug Bounty Sees 59 Percent Surge in March

For site owners and agency operators, validated vulnerabilities are disclosed to vendors through the Wordfence Vulnerability Management Portal, a free tool available to all WordPress plugin and theme developers that streamlines the responsible disclosure process.

Firewall rule coverage rolls out based on plan tier once a vulnerability is confirmed:

Plan Firewall Rule Coverage
Premium, Care, and Response Real-time, as soon as a vulnerability is confirmed
Free Same rules applied after a 30-day delay

Top contributors are named and credited in the monthly report. The program publishes its scope clearly and pays on a per-submission basis for validated findings.

Plugins and themes remain the largest source of reported WordPress vulnerabilities, and the Bug Bounty Program is one of several coordinated disclosure channels — alongside resources like the WPScan vulnerability database and individual vendor programs — aimed at closing the gap between discovery and patch deployment.