CyberRota Analysis
AI-GeneratedThe Link Factory WordPress plugin contains a critical backdoor vulnerability that exposes a REST API endpoint, allowing attackers to execute commands with operator control. This flaw can lead to unauthorized access and manipulation of the WordPress site, posing a severe risk to site integrity and data security. WordPress site administrators using this plugin should prioritize immediate remediation to mitigate potential exploitation.
Original NVD Description
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).