Review Vulnerability of WordPress Plugin -- 2
Budget / Salary$250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
# Independent WordPress Plugin Vulnerability Review
I am looking for an experienced WordPress security researcher / application security specialist to independently review a vulnerability finding in a WordPress plugin.
The finding has already been researched and documented against a recent plugin version. There is also a previously published vulnerability affecting earlier versions of the same plugin.
The objective is to determine whether our finding represents:
* a duplicate of the previously disclosed vulnerability;
* an incomplete fix or regression in the newer version;
* a technically distinct vulnerability variant;
* or an inconclusive result requiring additional evidence.
## Scope
The selected researcher will receive:
* our current vulnerability report;
* exact plugin version tested;
* HTTP request/response evidence;
* screenshots;
* reproduction notes;
* negative controls;
* relevant source-code observations;
* the public vulnerability disclosure for comparison.
The review should compare:
* affected version(s);
* vulnerable endpoint / route;
* parameters involved;
* authentication and authorization requirements;
* attacker preconditions;
* exploitation flow;
* security impact;
* HTTP evidence;
* screenshots and supporting artifacts;
* negative controls;
* differences from the previously disclosed vulnerability.
## Important restriction
This is a **documentary and technical review only**.
No testing against third-party websites, production systems, or external targets is required or authorized.
Any validation should be limited to the supplied evidence, source code, and/or a local controlled environment if necessary.
## Deliverable
A concise technical assessment containing:
1. Final verdict:
* Duplicate
* Incomplete fix / regression
* Distinct variant
* Inconclusive
2. Confidence level.
3. Evidence supporting the conclusion.
4. Evidence against the conclusion.
5. Identification of any missing evidence.
6. Recommended corrections or improvements to the vulnerability report before submission to a vulnerability disclosure program.
## Preferred experience
Strong experience with:
* WordPress plugin security;
* PHP application security;
* authentication / authorization vulnerabilities;
* REST and AJAX endpoint analysis;
* vulnerability disclosure programs;
* Patchstack, Wordfence, WPScan, CVE research, or similar ecosystems.
Experience independently validating vulnerability reports is especially valuable.
Please briefly describe previous WordPress vulnerability research or CVE / responsible disclosure experience when applying.
I am looking for an experienced WordPress security researcher / application security specialist to independently review a vulnerability finding in a WordPress plugin.
The finding has already been researched and documented against a recent plugin version. There is also a previously published vulnerability affecting earlier versions of the same plugin.
The objective is to determine whether our finding represents:
* a duplicate of the previously disclosed vulnerability;
* an incomplete fix or regression in the newer version;
* a technically distinct vulnerability variant;
* or an inconclusive result requiring additional evidence.
## Scope
The selected researcher will receive:
* our current vulnerability report;
* exact plugin version tested;
* HTTP request/response evidence;
* screenshots;
* reproduction notes;
* negative controls;
* relevant source-code observations;
* the public vulnerability disclosure for comparison.
The review should compare:
* affected version(s);
* vulnerable endpoint / route;
* parameters involved;
* authentication and authorization requirements;
* attacker preconditions;
* exploitation flow;
* security impact;
* HTTP evidence;
* screenshots and supporting artifacts;
* negative controls;
* differences from the previously disclosed vulnerability.
## Important restriction
This is a **documentary and technical review only**.
No testing against third-party websites, production systems, or external targets is required or authorized.
Any validation should be limited to the supplied evidence, source code, and/or a local controlled environment if necessary.
## Deliverable
A concise technical assessment containing:
1. Final verdict:
* Duplicate
* Incomplete fix / regression
* Distinct variant
* Inconclusive
2. Confidence level.
3. Evidence supporting the conclusion.
4. Evidence against the conclusion.
5. Identification of any missing evidence.
6. Recommended corrections or improvements to the vulnerability report before submission to a vulnerability disclosure program.
## Preferred experience
Strong experience with:
* WordPress plugin security;
* PHP application security;
* authentication / authorization vulnerabilities;
* REST and AJAX endpoint analysis;
* vulnerability disclosure programs;
* Patchstack, Wordfence, WPScan, CVE research, or similar ecosystems.
Experience independently validating vulnerability reports is especially valuable.
Please briefly describe previous WordPress vulnerability research or CVE / responsible disclosure experience when applying.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.