Impact
The FacturaONE para WooCommerce plugin before version 5.37 contains an unprotected request handler that relies on an empty cryptographic key when not configured. This flaw, identified as a code injection vulnerability (CWE-94), allows an unauthenticated attacker to write arbitrary files to a web-accessible directory, leading to remote code execution. The attacker has full control over the server, compromising confidentiality, integrity, and availability of the affected site.
Affected Systems
Affected products are the FacturaONE para WooCommerce plugin supplied by VeriFactu for WordPress sites. Any installation of the plugin before version 5.37 that has not overridden the default empty cryptographic key is vulnerable. The issue impacts all WordPress sites that host this plugin.
Risk and Exploitability
The CVSS base score of 9.0 rates this flaw as critical, and the EPSS score is less than 1%, indicating a very low exploitation probability. The vulnerability can be exploited by sending crafted HTTP requests to the vulnerable handler, which does not require authentication. Because the plugin writes files to a public directory, successful exploitation results in immediate remote code execution. The vulnerability is not listed in the CISA KEV catalog, but its high severity and lack of authentication barrier make it a high-risk threat.
OpenCVE Enrichment