Repository-specific security policies take precedence over this organization default.
Do not disclose exploitable details, credentials, production data or proof-of-concept payloads in a public issue.
When GitHub private vulnerability reporting is enabled for the affected repository, prefer that channel. Otherwise, contact the maintainers through a private channel identified by the project before sharing sensitive details.
Include enough information to validate the report safely:
- affected repository and version/commit;
- environment and prerequisites;
- minimal reproduction steps;
- expected security impact;
- suggested remediation, if known.
Security reports should concern code maintained by WP24Horas. Vulnerabilities in WordPress core, WooCommerce, third-party plugins, hosting providers or external services should be reported to the responsible upstream project.
Allow maintainers reasonable time to reproduce, fix and coordinate disclosure before publishing technical details.