Select Page

WiCyS

Vulnerability Rating Taxonomy (VRT)

Authentication & Data Context

Understanding our data classification is crucial for accurate vulnerability reporting. Please review the access levels and data types below.

Public Data

Data residing on the public-facing wicys.org website is considered public. Disclosures here generally carry a lower risk priority.

 

Member Portal (PII)

Access requires password and Multi-Factor Authenticator (MFA). Members are strictly authorized to view and edit only their own Personally Identifiable Information.

Confidential Data

Data outside of Public and/or Member Portal (PII) data is considered confidential and limited specifically to WiCyS internal staff.

Interactive Taxonomy Explorer

Filter and explore specific vulnerabilities by their priority level to understand how we classify risk across our tech stack.

Showing all 16 vulnerability classifications

Priority VRT Category Specific Vulnerability Variant / Affected Function
P1 Broken Access Control Privilege Escalation Accessing Confidential Financial, Partner, or Donor Data
P1 Broken Authentication Authentication Bypass Bypassing Multi-Factor Authentication (MFA) requirements
P1 Broken Authentication Authentication Bypass Admin access to core CMS or CRM platforms
P1 Server-Side Injection Remote Code Execution (RCE) Core CMS, Themes, or Plugins
P1 Server-Side Injection SQL Injection (SQLi) Full Database Read/Write Access
P2 Broken Access Control Insecure Direct Object Reference (IDOR) Viewing/Modifying other members' PII via the member portal
P2 Cross-Site Scripting (XSS) Stored Executing in Member Portal or Admin Context
P2 Server Security Misconfig Sensitive Information Disclosure API Token/Key leakage for Third-Party Integrations
P2 Broken Authentication Improper Session Management Session Hijacking / Fixation
P3 Cross-Site Scripting (XSS) Reflected Public-facing website
P3 Cross-Site Request Forgery (CSRF) Form Action Modifying member profiles or third-party/CMS form actions
P3 Broken Access Control Insecure Direct Object Reference (IDOR) Accessing non-PII, internal metadata
P4 Server Security Misconfig Information Disclosure Non-sensitive data / Public Data
P4 Unvalidated Redirects Open Redirect CMS or CRM authentication flows
P4 Application-Level DoS Rate Limiting Lack of rate limiting on non-authenticated forms
P5 Security Best Practices Missing Headers / Records Missing SPF/DMARC, missing security headers, server version disclosure

Strictly Out of Scope

Please do not submit reports for, or actively test, the following scenarios.

1. Core Infrastructure

Vulnerabilities inherent to the underlying infrastructure of WP Engine, Salesforce, or our integration partners (Google, PandaDoc, Zoho, etc.).

2. Volumetric Attacks

Any form of Denial of Service (DoS) or Distributed Denial of Service (DDoS) against WiCyS networks or applications.

3. Social Engineering

Phishing, vishing, tailgating, or any physical attacks against WiCyS staff, facilities, or members.

4. Third-Party Managed Apps

Can be reported only. No physical attacks can be performed on these systems.