The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Link Factory WordPress plugin is a sophisticated supply-chain attack vector masquerading as legitimate homepage publishing functionality. This critical vulnerability (CVSS 10.0) implements a backdoor with operator-controlled REST API endpoints that allow remote code execution and system compromise. Any WordPress installation using this plugin becomes a persistent foothold for attackers, with the vulnerability particularly dangerous because it bypasses standard authentication mechanisms through cryptographic verification against a hardcoded public key. Organizations relying on WordPress plugins without rigorous vetting—from small businesses to enterprises—face complete system compromise, data exfiltration, and lateral movement capabilities.
While MITRE ATT&CK techniques are not formally mapped to this CVE, Casky's extended reasoning capabilities would detect the attack patterns underlying this threat: unauthorized API access (T1190: Exploit Public-Facing Application), persistence through plugin installation (T1547: Boot or Logon Autostart Execution), and privilege escalation via cryptographic bypass mechanisms. Practitioners using Casky would identify indicators including suspicious /wp-json/link-factory/v1/ endpoint requests, unusual Ed25519 signature verification patterns in authentication logs, and anomalous REST API calls from unexpected sources. The absence of matching skills (0 mapped) highlights the novel attack methodology—Casky's Claude-powered analysis would flag this as an advanced persistent threat requiring immediate plugin audit, malware scanning, and detection of cryptographic key usage patterns across the WordPress environment.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15413. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation