top of page
perceptive_background_267k.jpg

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived f…

Published:

27 juli 2026 om 00:00:00

Alert date:

27 juli 2026 om 23:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

The FacturaONE para WooCommerce con VeriFactu WordPress plugin versions before 5.37 contains a critical unauthenticated remote code execution vulnerability. One of the plugin's request handlers lacks proper authentication, relying solely on a cryptographic key for protection. In the default, unconfigured state, this cryptographic key is empty, rendering the protection ineffective. Unauthenticated attackers can exploit this flaw to write arbitrary files into a web-accessible directory. Successful exploitation results in full remote code execution on the affected WordPress installation. The vulnerability is particularly dangerous because it requires no prior authentication or credentials. Sites running the plugin in its default state are immediately at risk without any additional configuration mistakes. Users are advised to update to version 5.37 or later to remediate the issue.

Technical details

Mitigation steps:

Affected products:

FacturaONE para WooCommerce con VeriFactu WordPress plugin (before 5.37)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page