# Security Policy

## Supported Versions

Only the Ultimate Multisite 2.x release series receives security updates. Security
fixes are delivered in the latest 2.x release; users should keep their installations
up to date rather than remain on an older 2.x version.

| Version | Security Updates |
| --- | --- |
| Ultimate Multisite 2.x | Supported (latest release) |
| WP Ultimo (legacy releases) | Not supported |
| All other release series | Not supported |

## Upgrade from WP Ultimo

Known vulnerabilities affect WP Ultimo, the predecessor to Ultimate Multisite.
All WP Ultimo users should upgrade to the latest Ultimate Multisite 2.x release.
Legacy WP Ultimo releases do not receive security updates.

## Reporting a Vulnerability

Please report suspected security vulnerabilities **privately** through
[GitHub's private vulnerability reporting form](https://github.com/Ultimate-Multisite/ultimate-multisite/security/advisories/new).
Do not disclose vulnerabilities in public issues, discussions, or pull requests.

To help us investigate, include:

- The affected plugin version and relevant WordPress and PHP versions.
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue, including any required permissions or configuration.
- A proof of concept, if available, without real credentials or personal data.

## Coordinated Disclosure

We review private reports, investigate confirmed vulnerabilities, and coordinate
with reporters on fixes and disclosure. Please allow us time to investigate and
make a fix available before publishing vulnerability details.

Confirmed security fixes are released for the supported Ultimate Multisite 2.x
series. When appropriate, we publish a GitHub security advisory describing the
affected versions, the fix, and recommended user actions.
