CVE-2026-14289

FacturaONE · FacturaONE para WooCommerce con VeriFactu

A code injection vulnerability in FacturaONE para WooCommerce con VeriFactu allows unauthenticated attackers to write arbitrary files to the server via an unauthenticated request handler.

Executive summary

A critical code injection vulnerability in the FacturaONE para WooCommerce con VeriFactu plugin allows unauthenticated attackers to achieve remote code execution through an improperly protected request handler.

Vulnerability

The plugin provides a request handler that lacks authentication and relies on a cryptographic key that remains empty in the default configuration. This allows an unauthenticated attacker to inject and write arbitrary files into web-accessible directories.

Business impact

This vulnerability enables full remote code execution, which permits an attacker to take control of the web server and access sensitive WooCommerce transaction data. Given the CVSS score of 9.0, the impact on business continuity and data privacy is extreme, as it effectively grants an attacker administrative capabilities over the store.

Remediation

Immediate Action: Update the FacturaONE para WooCommerce con VeriFactu plugin to version 5.37 or later.

Proactive Monitoring: Regularly scan the web-accessible directories for unexpected script files and review file modification timestamps for unauthorized changes.

Compensating Controls: Use a Web Application Firewall to filter incoming requests to the plugin's endpoints and ensure that the plugin is only accessible to authorized administrative IP addresses where possible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this flaw demands immediate remediation. Administrators should verify their plugin version and apply the update to version 5.37, as the default configuration state is highly susceptible to remote takeover.