CVE-2026-15413
CRITICAL
10,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
The Link Factory WordPress plugin is a backdoor. Distributed as a 'homepage sentence publisher', it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
https://wpscan.com/vulnerability/4cad269d-0146-4ca9-a1ae-55f02c8e5433/