Security fixes are prepared for the latest published version of each Lineweb plugin. If a report also affects an older release, update guidance will be included where practical. WordPress, WooCommerce, and PHP must meet the minimum versions declared by the affected plugin.
Do not open a public issue for a suspected vulnerability before a fix and coordinated disclosure are available.
Send the initial report through the Lineweb contact form and include:
- the plugin name and affected version;
- the WordPress, WooCommerce, and PHP versions used;
- clear reproduction steps or a minimal proof of concept;
- the security impact and required attacker permissions;
- whether the issue is already public or known to another party.
Never include live credentials, personal data, customer orders, private keys, or a production database export. If sensitive diagnostic material is necessary, request a secure transfer method in the initial report.
Lineweb will acknowledge a complete report, attempt to reproduce it on a supported release, assess its severity, and coordinate remediation and disclosure with the reporter. A narrowly scoped security fix and changelog entry will be published when disclosure is safe.
Good-faith research should use an installation you own or have explicit permission to test. Do not access third-party data, interrupt a live service, send unsolicited traffic, or use a discovered issue beyond the minimum needed to demonstrate impact.