PatchSiren

FacturaONE CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review FacturaONE CVE published 2026-07-27

CVE-2026-14289

CVE-2026-14289 is a vulnerability in the FacturaONE para WooCommerce con VeriFactu WordPress plugin before version 5.37. The plugin does not authenticate one of its request handlers, which relies on a cryptographic key that is empty by default. This allows unauthenticated attackers to write arbitrary files to a web-accessible directory, leading to remote code execution. The vulnerability has a high impact [truncated]