Wunderite
Bug Bounty Program

Introduction

Wunderite is committed to building secure software. We welcome security researchers to identify and responsibly disclose vulnerabilities in our web application, public APIs, and production infrastructure.

Scope

Eligible assets:

  • wunderite.com
  • app.wunderite.com
  • sandbox.wunderite.com
  • demo.wunderite.com
  • docs.wunderite.com (including publicly documented API endpoints)

Examples of qualifying vulnerabilities:

  • Remote Code Execution (RCE)
  • SQL Injection
  • XML External Entity (XXE) Injection
  • Authorization bypass or privilege escalation
  • Information disclosure (e.g., sensitive data leaks)
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)

Out-of-scope issues include:

  • Vulnerabilities that do not present a substantial or demonstrable security impact
  • Clickjacking, open redirects, or missing security headers
  • Denial of Service (DoS) or resource exhaustion attacks
  • Social engineering (e.g., phishing, pretexting)
  • Physical security or access to infrastructure
  • Attacks on local networks (e.g., ARP spoofing, DNS poisoning)
  • Use of automated scanners or fuzzers without prior authorization
  • Vulnerabilities in third-party services or platforms outside our control
  • Information leakage that does not expose sensitive data or pose a meaningful security risk (e.g., non-sequential IDs, generic error messages, benign response headers, server names, software versions)
  • Expected or documented behavior of third-party platforms we use, such as default WordPress functionality, or third-party platforms that we do not control. 

Rewards

Monetary rewards are offered for eligible findings, assessed case-by-case based on impact and severity.

  • Minimum bounty: $100 USD
  • Maximum bounty: not publicly disclosed


Typical resolution SLAs:

  • High severity: within 30 days
  • Medium severity: within 60 days
  • Low severity: within 90 days

Rules of Engagement

To participate in the program, researchers must:

  • Avoid any activity that could harm or degrade our systems
  • Not access, alter, or store any user data beyond what’s strictly necessary to demonstrate an issue
  • Only use accounts you own or have explicit permission to use
  • Submit all findings privately; public disclosure is not permitted without written consent, including posting generic statements about the potential vulnerability on social media
  • Cease testing immediately if sensitive data (e.g., PII, PHI, payment information) is encountered
  • Remain within the defined scope; out-of-scope findings are accepted for review but are not reward-eligible
  • Comply with all applicable laws and avoid illegal testing techniques
  • Include a clear and reproducible proof of concept (PoC) with each submission

Reporting Process

To report a vulnerability, email [email protected] with the following details:

  • Description of the vulnerability – A clear summary of the issue.
  • Steps to reproduce – Detailed, step-by-step instructions we can follow.
  • Proof of Concept (PoC) – Code, data, or configuration needed to demonstrate the issue.
  • Assessment of potential impact – Your evaluation of how this vulnerability could affect our systems or users.
  • Supporting evidence or context – Screenshots or a video demonstrating the issue are required. Reports without visual evidence will not be processed.

Note: This is a private, non-public program. Please do not share or discuss vulnerabilities outside of direct communication with Wunderite.

Disclosure & Resolution Policy

We commit to:

  • Acknowledging receipt of submissions within 3 business days
  • Providing an initial assessment within 10 business days
  • Addressing valid vulnerabilities based on the severity-based timelines above

Wunderite reserves the right to determine resolution priority, scope interpretation, and public disclosure timing.

Legal Safe Harbor

When conducted in accordance with this policy, we consider vulnerability research to be:

  • Authorized and legal under the Computer Fraud and Abuse Act (CFAA)
  • Exempt from Digital Millennium Copyright Act (DMCA) enforcement
  • Performed in good faith to improve our security posture

Participants agree to indemnify Wunderite and its affiliates from any liability arising from participation. Unauthorized or malicious activity outside this policy may result in legal action.

Thank You

We appreciate your efforts to help secure Wunderite. Your contributions support our mission to provide a safer and more reliable platform for everyone.

Last Updated: June 25, 2025th