Although we strive to create the most secure products possible, we are not perfect. If you happen to find a security vulnerability in one of our services, we would appreciate letting us know and allowing us to respond before disclosing the issue publicly. We take security seriously, and we will try to review and reply to every legitimate security report personally within 24 hours.
(Source)
For responsible disclosure of security issues and to be eligible for our bug bounty program, please submit security issues via the HackerOne portal: https://hackerone.com/automattic
Please do not open public GitHub issues for security reports.
Security fixes are issued against the latest minor release of Zoninator. Earlier versions do not receive backports. The current supported version is listed in the README and on WordPress.org.