PT-2026-64848 · WordPress · Facturaone Para Woocommerce Con Verifactu

·

CVE-2026-14289

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FacturaONE para WooCommerce con VeriFactu WordPress plugin versions prior to 5.37
Description An authentication failure in a request handler allows unauthenticated attackers to write arbitrary files into a web-accessible directory. This occurs because the handler relies on a cryptographic key that remains empty by default in an unconfigured state, leading to remote code execution.
Recommendations Update the plugin to version 5.37 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14289

Affected Products

Facturaone Para Woocommerce Con Verifactu