What is CVE-2026-14289?
This vulnerability affects the FacturaONE para WooCommerce con VeriFactu WordPress plugin before version 5.37, where an unauthenticated request handler exists due to an empty cryptographic key in its default state. Attackers can write arbitrary files to the server, potentially leading to remote code execution. It is recommended to update to the latest patched version of the plugin.
Azərbaycanca: Bu boşluq FacturaONE para WooCommerce con VeriFactu WordPress plaginin 5.37-dən əvvəlki versiyalarına təsir edir, burada istifadə olunmayan boş kriptoqrafik açar səbəbindən autentifikasiya olunmamış sorğu idarəedicisi var. Təcavüzkarlar serverə ixtiyari fayl yazaraq uzaqdan kod icrasına nail ola bilərlər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
How does the FacturaONE para WooCommerce con VeriFactu plugin use an empty cryptographic key?
In its default state, the plugin has an empty cryptographic key, which results in an unauthenticated request handler.
What can an attacker achieve by successfully exploiting CVE-2026-14289?
Attackers can write arbitrary files to the server, potentially leading to remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.