The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id. | |
| Title | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update REST Endpoint | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-06T06:00:21.148Z
Reserved: 2026-09-11T12:16:44.634Z
Link: CVE-2026-89289
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.