docs/contribution/releases/security-support.md
WooCommerce provides security patches for the last 21 major versions. If the current stable WooCommerce version is 11.0, that means version 9.0 and newer.
"Major version" follows WooCommerce's release numbering (10.8, 10.9, 11.0, ...), not semantic versioning. At the current release cadence, 21 major versions correspond to roughly two years of releases.
For critical vulnerabilities - actively exploited, or with severe impact (for example CVSS 9.0+) - the security team may patch versions beyond the standard window. How far back to patch is at the security team's discretion, weighing exploitation risk against the affected install base.
Security vulnerabilities must be reported privately through Automattic's HackerOne program: https://hackerone.com/automattic/. Never report them in public issues.
The release run-book's publish steps include moving the supported-version floor forward when the stable release of a new major version ships.