CVE-2026-15413 (CVSS 10.0): The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp- (opens in a new tab)
Why readA WordPress plugin marketed as a homepage sentence publisher is a deliberate backdoor, and it ships a hunting artefact you can grep for today.
Link Factory exposes an operator-controlled REST API at /wp-json/link-factory/v1/, gated by a detached Ed25519 signature checked against a hardcoded operator public key, with the health check left open. The signature scheme means the channel is usable only by whoever holds the private key, so this is a maintained access channel rather than sloppy code, and every version is affected. Check managed WordPress estates for that route and for the plugin slug; a CVE number does not make this a patching problem, it makes it an eviction problem.