Backdoor in Link Factory WordPress Plugin Exposes REST API
CVE-2026-15413
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2026-15413?
The Link Factory plugin for WordPress is compromised by a backdoor that enables unauthorized access via an operator-controlled REST API endpoint located at /wp-json/link-factory/v1/. This backdoor is authenticated using a detached Ed25519 signature, which is verified against a hardcoded public key specific to the operator, allowing potential attackers to exploit the plugin. This creates a significant security risk for WordPress sites utilizing this plugin, making them vulnerable to unauthorized operations.
Affected Version(s)
Link Factory 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved