
🚪 Backdoor: CVE-2026-15413 — "Link Factory" WordPress plugin is malicious. Hides a REST API at /wp-json/link-factory/v1/ giving operators remote control. CVSS 10. Remove it now. #cybersecurity #wordpress #ciso #msp #vulnerabilities https://secalerts.co/vulnerability/CVE-2026-15413?utm_campaign=x https://t.co/QwA8eInKoa
Post summary
A new backdoor vulnerability (CVE‑2026‑15413) was disclosed in the Link Factory WordPress plugin, exposing a hidden REST API that can be used for remote control. The advisory urges users to remove the plugin immediately.
