CVE-2026-89289 PUBLISHED

Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update REST Endpoint

Assigner: WPScan
Reserved: 11.09.2026 Published: 06.10.2026 Updated: 06.10.2026

The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.

Product Status

Vendor Unknown
Product Fast Courier
Versions Default: unknown
  • affected from 0 to 5.2.3 (incl.)

Credits

  • Enrico Marcolini - Claudio Marchesini - Dottor Marc finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE