Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-15413: Link Factory WordPress Plugin - Unsecured Admin Access
CVE-2026-15413 · published 22 days ago
Summary
The Link Factory WordPress plugin contains a hidden backdoor that allows unauthorized access to the plugin's functionality. This could allow an attacker to manipulate or steal sensitive data, posing a significant risk to websites using the plugin. Update the plugin to the latest version to address this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | link factory | <= * |
Original advisory text
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a deta...
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
References
- https://wpscan.com/vulnerability/4cad269d-0146-4ca9-a1ae-55f02c8e5433/ exploit vdb-entry technical-description
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-912Hidden Functionality
Timeline
Published13 Aug 2026
Updated29 Aug 2026
First seen13 Aug 2026
Monitor software like this
Free during beta