CVE-2026-15413

Published: Ago 13, 2026 Last Modified: Ago 13, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 10,0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

The Link Factory WordPress plugin is a backdoor. Distributed as a 'homepage sentence publisher', it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).

https://wpscan.com/vulnerability/4cad269d-0146-4ca9-a1ae-55f02c8e5433/