


Perceptive Security
SOC/SIEM Consultancy

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived f…
Published:
27 juli 2026 om 00:00:00
Alert date:
27 juli 2026 om 23:04:07
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
The FacturaONE para WooCommerce con VeriFactu WordPress plugin versions before 5.37 contains a critical unauthenticated remote code execution vulnerability. One of the plugin's request handlers lacks proper authentication, relying solely on a cryptographic key for protection. In the default, unconfigured state, this cryptographic key is empty, rendering the protection ineffective. Unauthenticated attackers can exploit this flaw to write arbitrary files into a web-accessible directory. Successful exploitation results in full remote code execution on the affected WordPress installation. The vulnerability is particularly dangerous because it requires no prior authentication or credentials. Sites running the plugin in its default state are immediately at risk without any additional configuration mistakes. Users are advised to update to version 5.37 or later to remediate the issue.
Technical details
Mitigation steps:
Affected products:
FacturaONE para WooCommerce con VeriFactu WordPress plugin (before 5.37)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14289
https://wpscan.com/vulnerability/f08365f6-57d2-475a-82c8-c4d27286569e/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
