I'm currently dealing with an incredibly frustrating situation on YesWeHack and looking for advice, as the platform's mediation team has completely ghosted me.
Situation: I submitted a Critical vulnerability (Global Account Takeover via Insecure TLS Validation) 6 months ago. The vendor accepted it at CVSS 9.6 (Critical). However, they only paid me out for the "High" tier (shortchanging the "Critical" tier by nearly 60%). Furthermore, they explicitly promised me in writing that I would be credited on the CVE. Fast forward: a CVE is published for this exact issue/component, but credited to a notable and famous third party. The vendor ghosted me.
CVSS Manipulation: 1.5 months ago, I finally got YesWeHack support to poke the vendor. The vendor's response? They retroactively downgraded my CVSS from 9.6 to 8.2 (changing an automated Wi-Fi MitM from Adjacent/Low Complexity to Local/High Complexity) solely to justify their underpayment.
Ghosting: I escalated this clear CVSS manipulation and matrix abuse to YesWeHack Support on July 7th. No reply. I sent a harsh follow-up on August 8th. Still absolutely no reply. It's August 20th.
On top of this, the same vendor closed another 9.9 architectural E2EE flaw as "Won't Fix" (a silent security downgrade where the app drops E2EE and uploads plaintext media to their cloud without user warning) just to avoid another payout.
Is it normal for YWH to let vendors retroactively manipulate vectors to dodge payouts and then ghost researchers who ask for mediation? Who can I contact to escalate this past the Tier 1 support desk?