Security fixes are provided for the latest released version of Mosaicora for WordPress. Older versions may be asked to upgrade before receiving a fix.
Do not open a public issue for a suspected vulnerability.
Use GitHub private vulnerability reporting in this repository. If that channel
is unavailable, email support@mosaicora.io with:
- the affected version;
- a clear description of the impact;
- safe reproduction steps or a proof of concept;
- any suggested remediation or disclosure timeline.
Please avoid accessing data that is not yours, disrupting services, or publicly disclosing the issue before maintainers have had a reasonable opportunity to investigate and release a fix. Mosaicora will acknowledge a complete report and coordinate next steps privately.