GHSA-r2m9-vxc3-w8phMediumCVSS 5.3

The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route...

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.

🔗 References (3)