← WordPress Vulnerabilities
WordPress security by component

FacturaONE para WooCommerce con VeriFactu

FacturaONE para WooCommerce con VeriFactu is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.

Plugin slug: facturaone-para-woocommerce-con-verifactu

CVE-2026-14289: FacturaONE unauthenticated file write can lead to code execution

FacturaONE para WooCommerce con VeriFactu before 5.37 exposes a request handler that relies only on a key which is empty when the plugin has not been configured. An unauthenticated attacker can reach that handler on a default or unconfigured installation and write an arbitrary file into a web-accessible directory; writing executable PHP can result in remote code execution. The CNA record does not identify the handler, action, parameters or file-writing function.

PublishedJul 27, 2026
Known safe version5.37
Safe version
Jul 27, 2026 CVE-2026-14289
FacturaONE unauthenticated file write can lead to code execution
FacturaONE para WooCommerce con VeriFactu before 5.37 exposes a request handler that relies only on a key which is empty when the plugin has not been configured. An unauthenticated attacker can reach that handler on a default or unconfigured installation and write an arbitrary file into a web-accessible directory; writing executable PHP can result in remote code execution. The CNA record does not identify the handler, action, parameters or file-writing function.
5.37
CVE9.0
NVDPending