Junglewise Threat Intelligence

CVE-2026-14289: FacturaONE para WooCommerce unauthenticated RCE in request handler

CVE-2026-14289 · Severity: info · CVSS 9 · Published 2026-07-27

Executive brief

A vulnerability in the FacturaONE plugin for WooCommerce allows unauthorized individuals to take complete control of a website. This plugin is used to manage invoicing and tax compliance for online stores. An attacker can exploit this flaw to upload malicious files, potentially leading to the theft of customer data, website defacement, or a total service outage.

Technical details

The FacturaONE plugin fails to implement proper authentication for a specific request handler. The handler relies on a cryptographic key for security; however, in its default, unconfigured state, this key is empty. An unauthenticated remote attacker can exploit this to write arbitrary files into web-accessible directories, leading to Remote Code Execution (RCE). Additionally, the same handler can be abused for Server-Side Request Forgery (SSRF) and arbitrary URL redirection. The issue is resolved in version 5.37.

Affected products

  • FacturaONE FacturaONE para WooCommerce con VeriFactu < 5.37

Timeline

  • 2026-07-06: disclosed: Initial public disclosure by WPScan
  • 2026-07-27: advisory: CVE published to NVD
  • 2026-07-27: patched: Fix confirmed in version 5.37

References