CVE-2026-14289
Description
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | FacturaONE para WooCommerce con VeriFactu | — | 0 < 5.37 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-94 Improper Control of Generation of Code ('Code Injection') |