CVE-2026-14289
FacturaONE · FacturaONE para WooCommerce con VeriFactu
A code injection vulnerability in FacturaONE para WooCommerce con VeriFactu allows unauthenticated attackers to write arbitrary files to the server via an unauthenticated request handler.
Executive summary
A critical code injection vulnerability in the FacturaONE para WooCommerce con VeriFactu plugin allows unauthenticated attackers to achieve remote code execution through an improperly protected request handler.
Vulnerability
The plugin provides a request handler that lacks authentication and relies on a cryptographic key that remains empty in the default configuration. This allows an unauthenticated attacker to inject and write arbitrary files into web-accessible directories.
Business impact
This vulnerability enables full remote code execution, which permits an attacker to take control of the web server and access sensitive WooCommerce transaction data. Given the CVSS score of 9.0, the impact on business continuity and data privacy is extreme, as it effectively grants an attacker administrative capabilities over the store.
Remediation
Immediate Action: Update the FacturaONE para WooCommerce con VeriFactu plugin to version 5.37 or later.
Proactive Monitoring: Regularly scan the web-accessible directories for unexpected script files and review file modification timestamps for unauthorized changes.
Compensating Controls: Use a Web Application Firewall to filter incoming requests to the plugin's endpoints and ensure that the plugin is only accessible to authorized administrative IP addresses where possible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this flaw demands immediate remediation. Administrators should verify their plugin version and apply the update to version 5.37, as the default configuration state is highly susceptible to remote takeover.