CVE-2026-14289 PUBLISHED

WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution

Assigner: WPScan
Reserved: 01.07.2026 Published: 27.07.2026 Updated: 27.07.2026

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.

Product Status

Vendor Unknown
Product FacturaONE para WooCommerce con VeriFactu
Versions Default: unaffected
  • affected from 0 to 5.37 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE