AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-15413

CRITICAL · CVSS 10 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Link Factory WordPress plugin contains a critical backdoor vulnerability that exposes a REST API endpoint, allowing attackers to execute commands with operator control. This flaw can lead to unauthorized access and manipulation of the WordPress site, posing a severe risk to site integrity and data security. WordPress site administrators using this plugin should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-15413
Severity
CRITICAL
CVSS
10
EPSS
0.29%
WordPress

Original NVD Description

The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).