What is CVE-2026-15413?
The 'Link Factory' WordPress plugin is actually a backdoor. It exposes an operator-controlled REST API at /wp-json/link-factory/v1/, authenticated via a specific key. It is recommended to remove this plugin immediately.
Azərbaycanca: "Link Factory" WordPress plagini əslində bir backdoor-dur. O, /wp-json/link-factory/v1/ üzərindən operator tərəfindən idarə olunan REST API təqdim edir və bu API xüsusi açarla autentifikasiya olunur. Bu plagini dərhal silmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
What CVE is associated with the 'Link Factory' WordPress plugin?
The 'Link Factory' plugin is associated with CVE-2026-15413 and acts as a backdoor.
What security measure should be taken regarding the 'Link Factory' plugin?
The plugin should be removed immediately as it exposes an operator-controlled REST API authenticated via a specific key.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.