---
id: CVE-2026-89289
title: >-
  The Fast Courier  WordPress plugin through 5.2.3 does not restrict an
  unauthenticated REST route that writes order fulfillment data, allowing
  unauthenticated attackers to overwrite the courier status and customer-facing
  tracking details …
summary: >-
  The Fast Courier  WordPress plugin through 5.2.3 does not restrict an
  unauthenticated REST route that writes order fulfillment data, allowing
  unauthenticated attackers to overwrite the courier status and customer-facing
  tracking details …
severity: none
cwe:
  - CWE-862
product: Fast Courier
affected:
  - fast_courier <= 5.2.3
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:16:59.737'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89289'
references:
  - url: 'https://wpscan.com/vulnerability/716b6d58-a816-43f2-8a1a-b9fe4f2f9d1d/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T06:48:36.103Z'
---

## Overview

The Fast Courier  WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
