CVE-2026-89289: Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update REST Endpoint
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker who can reach the affected site's REST endpoint can exploit it. No WordPress or WooCommerce account is required.
What does an attacker need to alter an order's fulfillment information?
The attacker needs the ID of the WooCommerce order they want to target. They can then supply that ID to overwrite the courier status and customer-facing tracking details.
Which installations are affected?
Fast Courier WordPress plugin versions through 5.2.3 are affected. The issue is in an unauthenticated REST route, so sites exposing the plugin's normal REST functionality are at risk.
How can I tell whether an order may have been tampered with?
Review WooCommerce orders for unexpected changes to courier status or customer-facing tracking details. Compare those values with the fulfillment information held by the legitimate courier or order-processing workflow.