WordPress security by component
FacturaONE para WooCommerce con VeriFactu
Plugin description
FacturaONE para WooCommerce con VeriFactu is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.
Plugin slug:
facturaone-para-woocommerce-con-verifactuLatest vulnerability
CVE-2026-14289: FacturaONE unauthenticated file write can lead to code execution
FacturaONE para WooCommerce con VeriFactu before 5.37 exposes a request handler that relies only on a key which is empty when the plugin has not been configured. An unauthenticated attacker can reach that handler on a default or unconfigured installation and write an arbitrary file into a web-accessible directory; writing executable PHP can result in remote code execution. The CNA record does not identify the handler, action, parameters or file-writing function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-14289
FacturaONE unauthenticated file write can lead to code execution
FacturaONE para WooCommerce con VeriFactu before 5.37 exposes a request handler that relies only on a key which is empty when the plugin has not been configured. An unauthenticated attacker can reach that handler on a default or unconfigured installation and write an arbitrary file into a web-accessible directory; writing executable PHP can result in remote code execution. The CNA record does not identify the handler, action, parameters or file-writing function.
|
5.37 |
CVE9.0
NVDPending
|