Description
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.
Published:
2026-10-06
Score:
n/a
EPSS:
n/a
KEV:
No
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id. | |
| Title | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update REST Endpoint | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-06T06:00:21.148Z
Reserved: 2026-09-11T12:16:44.634Z
Link: CVE-2026-89289
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.