The Link Factory WordPress plugin does exactly what it’s supposed to do. And that’s the problem and why it earned a perfect CVSS 10.0 critical vulnerability score.
The WordPress plugin was marketed as a handy SEO tool – something that would automatically drop a few polished sentences onto a website’s homepage to help it rank higher on Google. Security researchers who tore it apart this month found its real purpose is different. It quietly hands over control of the website to whoever distributed it.
Researcher Erwan LR at WPScan, a firm that tracks WordPress security threats, published the findings August 11 and didn’t mince words. “The plugin is a backdoor,” the advisory states.
“The PoC will be displayed on August 25, 2026, to give users the time to update,” according to WPScan’s vulnerability writeup on the CVE tracked as CVE-2026-15413. The CVE record indicates that the “flaw” can be exploited remotely without a login or any action from the site owner, and successful exploitation can expose data, alter the site and potentially knock the website offline.
Researcher’s Writeup Warns
According to Erwan LR, the plugin gives its operator a secret way into the WordPress site that bypasses the site’s normal login system, according to WPScan.
Once the plugin is installed, the operator can remotely create a hidden administrator account, get the username and password for it, check whether that account still exists, and delete it when they’re done. They can also publish or remove posts while making them appear to have been written by a legitimate site administrator.
The operator can also quietly insert their own HTML and links into the site’s footer. That content can be hidden off-screen so normal visitors don’t see it, while search engines still may. This makes it useful for things such as spammy backlink schemes or black-hat SEO, according to the researcher.
The plugin also exposes a public status check that lets someone determine whether Link Factory is installed on a site and which version is running. According to WPScan, the operator does not need the website owner’s WordPress credentials to do any of this. The plugin creates its own separate access path. So even if the owner changes their password, the Link Factory operator can retain control as long as the plugin remains installed.
In security terms, that’s effectively persistent administrator-level access built into the plugin itself.
Link Factory Rabbit Hole
There is no public WordPress.org download page or official installation count that I can find. That means it’s unclear how many sites are running Link Factory or how or why site owners obtained it.
Link Factory appears to have been used as a suspected black-hat SEO network tool, with public traces going back months before its CVE disclosure.
A search by Security Point Break found search engines have indexed complete link-factory directories on live WordPress installations, including the PHP files and its own readme.txt. One exposed copy shows Link Factory version 3.0.0 installed in July. (SPB is purposely not sharing the name of impacted domains)
Its own readme.txt describes Link Factory innocuously as a “Sentence publisher for Link Factory workflow,” with WordPress tags including SEO, homepage, footer and links.
The changelog, the developer’s version history, sheds light on the developer’s intentions. Version 3 added remotely controlled administrator-user management, article publishing and sitewide content placement. An earlier version added the ability to position footer content off-screen so visitors would not see it. The readme also says a backend system checks the plugin’s protocol version and can reinstall outdated installations during verification.
This indicates Link Factory is likely not simply an SEO plugin with a dangerous bug. It appears to provide a centralized operator with a persistent management channel into participating WordPress sites. The exposed package even contains separate modules for articles, users, signatures, health checks and sentence management.
Still unknown is who operates Link Factory, where the plugin was distributed, whether site owners knowingly installed it as part of an SEO/link-building service, and how many sites are or were enrolled.
WordPress’s Plugin Problem
It’s not the only related case this year. On July 31, an old server that WPManageNinja — maker of Fluent Forms Pro and Ninja Tables Pro — thought it had shut down years ago got hacked, and pushed tampered versions of both plugins to customers for five hours. About 295 people downloaded the bad version, which planted a hidden, password-free admin login.
WPScan’s own database lists more from this year: Smart Slider 3 Pro, MonsterInsights Pro, Enable CORS, and Advanced Responsive Video Embedder all shipped backdoors through their own official update channels.
The pattern playing out here is; no website owner had to make a mistake. The bad code arrived through the update system people are told to trust.
That leaves two things worth checking on any WordPress site — not just ones running Link Factory, Fluent Forms Pro, or the others named above: the wp-content/mu-plugins folder, which loads automatically and never shows up in the normal plugins list, and the admin-user list, for accounts nobody remembers creating.