SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14289

CRITICAL · CVSS 9 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The FacturaONE plugin for WooCommerce prior to version 5.37 is vulnerable due to a lack of authentication in one of its request handlers, which is only secured by an empty cryptographic key by default. This flaw allows unauthenticated attackers to write arbitrary files to a web-accessible directory, potentially leading to remote code execution. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the critical risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14289
Severity
CRITICAL
CVSS
9
EPSS
0.40%
WordPress

Original NVD Description

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.