Review
FacturaONE
CVE published 2026-07-27
CVE-2026-14289
CVE-2026-14289 is a vulnerability in the FacturaONE para WooCommerce con VeriFactu WordPress plugin before version 5.37. The plugin does not authenticate one of its request handlers, which relies on a cryptographic key that is empty by default. This allows unauthenticated attackers to write arbitrary files to a web-accessible directory, leading to remote code execution. The vulnerability has a high impact [truncated]