WiCyS
Vulnerability Rating Taxonomy (VRT)
Authentication & Data Context
Understanding our data classification is crucial for accurate vulnerability reporting. Please review the access levels and data types below.
Public Data
Data residing on the public-facing wicys.org website is considered public. Disclosures here generally carry a lower risk priority.
Member Portal (PII)
Access requires password and Multi-Factor Authenticator (MFA). Members are strictly authorized to view and edit only their own Personally Identifiable Information.
Confidential Data
Data outside of Public and/or Member Portal (PII) data is considered confidential and limited specifically to WiCyS internal staff.
Interactive Taxonomy Explorer
Filter and explore specific vulnerabilities by their priority level to understand how we classify risk across our tech stack.
Showing all 16 vulnerability classifications
| Priority | VRT Category | Specific Vulnerability | Variant / Affected Function |
|---|---|---|---|
| P1 | Broken Access Control | Privilege Escalation | Accessing Confidential Financial, Partner, or Donor Data |
| P1 | Broken Authentication | Authentication Bypass | Bypassing Multi-Factor Authentication (MFA) requirements |
| P1 | Broken Authentication | Authentication Bypass | Admin access to core CMS or CRM platforms |
| P1 | Server-Side Injection | Remote Code Execution (RCE) | Core CMS, Themes, or Plugins |
| P1 | Server-Side Injection | SQL Injection (SQLi) | Full Database Read/Write Access |
| P2 | Broken Access Control | Insecure Direct Object Reference (IDOR) | Viewing/Modifying other members' PII via the member portal |
| P2 | Cross-Site Scripting (XSS) | Stored | Executing in Member Portal or Admin Context |
| P2 | Server Security Misconfig | Sensitive Information Disclosure | API Token/Key leakage for Third-Party Integrations |
| P2 | Broken Authentication | Improper Session Management | Session Hijacking / Fixation |
| P3 | Cross-Site Scripting (XSS) | Reflected | Public-facing website |
| P3 | Cross-Site Request Forgery (CSRF) | Form Action | Modifying member profiles or third-party/CMS form actions |
| P3 | Broken Access Control | Insecure Direct Object Reference (IDOR) | Accessing non-PII, internal metadata |
| P4 | Server Security Misconfig | Information Disclosure | Non-sensitive data / Public Data |
| P4 | Unvalidated Redirects | Open Redirect | CMS or CRM authentication flows |
| P4 | Application-Level DoS | Rate Limiting | Lack of rate limiting on non-authenticated forms |
| P5 | Security Best Practices | Missing Headers / Records | Missing SPF/DMARC, missing security headers, server version disclosure |
Strictly Out of Scope
Please do not submit reports for, or actively test, the following scenarios.
1. Core Infrastructure
Vulnerabilities inherent to the underlying infrastructure of WP Engine, Salesforce, or our integration partners (Google, PandaDoc, Zoho, etc.).
2. Volumetric Attacks
Any form of Denial of Service (DoS) or Distributed Denial of Service (DDoS) against WiCyS networks or applications.
3. Social Engineering
Phishing, vishing, tailgating, or any physical attacks against WiCyS staff, facilities, or members.
4. Third-Party Managed Apps
Can be reported only. No physical attacks can be performed on these systems.