Remote Code Execution Vulnerability in FacturaONE Plugin for WooCommerce
CVE-2026-14289
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2026
Badges
What is CVE-2026-14289?
The FacturaONE plugin for WooCommerce prior to version 5.37 holds a critical security flaw that lacks proper authentication mechanisms for one of its request handlers. This oversight stems from a default empty cryptographic key, exposing the plugin to unauthenticated attackers. Such attackers can exploit this vulnerability to write arbitrary files within a web-accessible directory, potentially leading to remote code execution. This could compromise the integrity and security of affected WordPress installations.
Affected Version(s)
FacturaONE para WooCommerce con VeriFactu 0 < 5.37
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.