Description
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.
Published: 2026-07-27
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The FacturaONE para WooCommerce plugin before version 5.37 contains an unprotected request handler that relies on an empty cryptographic key when not configured. This flaw, identified as a code injection vulnerability (CWE-94), allows an unauthenticated attacker to write arbitrary files to a web-accessible directory, leading to remote code execution. The attacker has full control over the server, compromising confidentiality, integrity, and availability of the affected site.

Affected Systems

Affected products are the FacturaONE para WooCommerce plugin supplied by VeriFactu for WordPress sites. Any installation of the plugin before version 5.37 that has not overridden the default empty cryptographic key is vulnerable. The issue impacts all WordPress sites that host this plugin.

Risk and Exploitability

The CVSS base score of 9.0 rates this flaw as critical, and the EPSS score is less than 1%, indicating a very low exploitation probability. The vulnerability can be exploited by sending crafted HTTP requests to the vulnerable handler, which does not require authentication. Because the plugin writes files to a public directory, successful exploitation results in immediate remote code execution. The vulnerability is not listed in the CISA KEV catalog, but its high severity and lack of authentication barrier make it a high-risk threat.

Generated by OpenCVE AI on August 3, 2026 at 18:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FacturaONE para WooCommerce to version 5.37 or later.
  • If upgrading is not immediately possible, configure a non-empty cryptographic key to disable the vulnerable request handler.
  • Restrict write permissions on the web-accessible directory or move it outside the public web root.

Generated by OpenCVE AI on August 3, 2026 at 18:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Facturaone Para Woocommerce Con Verifactu
Facturaone Para Woocommerce Con Verifactu facturaone Para Woocommerce Con Verifactu
Wordpress
Wordpress wordpress
Vendors & Products Facturaone Para Woocommerce Con Verifactu
Facturaone Para Woocommerce Con Verifactu facturaone Para Woocommerce Con Verifactu
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.
Title WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution
References

Subscriptions

Facturaone Para Woocommerce Con Verifactu Facturaone Para Woocommerce Con Verifactu
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-27T17:33:53.457Z

Reserved: 2026-07-01T08:06:07.667Z

Link: CVE-2026-14289

cve-icon Vulnrichment

Updated: 2026-07-27T17:32:24.969Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T07:16:25.890

Modified: 2026-07-27T20:33:01.673

Link: CVE-2026-14289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:15:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')