Report security vulnerabilities privately through the reporting process on Automattic's security page. That page links to Automattic's HackerOne portal and its current program details.
Please include the affected endpoint or file, steps to reproduce, and the impact. Do not include access tokens, passwords, or other people's private data in a public issue.
For account or setup help, use Automattic support.