CVE-2026-89289 UNKNOWN

CVE-2026-89289

Published: 2026-10-06

Description

The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…