{"id":"CVE-2026-89289","title":"The Fast Courier  WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details …","summary":"The Fast Courier  WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details …","severity":"none","cwe":["CWE-862"],"product":"Fast Courier","affected":["fast_courier <= 5.2.3"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T07:16:59.737","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89289","references":[{"url":"https://wpscan.com/vulnerability/716b6d58-a816-43f2-8a1a-b9fe4f2f9d1d/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T06:48:36.103Z","slug":"CVE-2026-89289","body":"## Overview\n\nThe Fast Courier  WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}