VYPR

Fast Courier

by WordPress

CVEs (1)

  • CVE-2026-89289Oct 6, 2026
    risk 0.00cvss —epss —

    The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its…