CVE-2026-89289 Overview
CVE-2026-89289 affects the Fast Courier WordPress plugin through version 5.2.3. The plugin exposes an unauthenticated REST API route that writes order fulfillment data without access checks. Unauthenticated attackers can overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its order id.
The weakness maps to [CWE-862: Missing Authorization]. It permits remote tampering with order tracking records that merchants and customers rely on for shipment visibility.
Critical Impact
Remote, unauthenticated attackers can rewrite courier status and tracking details of arbitrary WooCommerce orders, enabling fraud, customer confusion, and operational disruption.
Affected Products
- Fast Courier WordPress plugin versions through 5.2.3
- WordPress sites running WooCommerce with Fast Courier enabled
- Merchant storefronts exposing the plugin's REST route to the public internet
Discovery Timeline
- 2026-10-06 - CVE-2026-89289 published to NVD
- 2026-10-06 - Last updated in NVD database
- Reference: WPScan Vulnerability Report
Technical Details for CVE-2026-89289
Vulnerability Analysis
The Fast Courier plugin registers a REST API route intended to receive order fulfillment updates. The route handler does not call a permission_callback that validates the caller. As a result, any unauthenticated HTTP client can invoke the endpoint and submit updates. The handler accepts an order id and writes attacker-controlled courier status and tracking data into the WooCommerce order record.
Because WooCommerce surfaces tracking details to customers through order emails and account pages, tampered values propagate directly to end users. Attackers can mark unshipped orders as delivered, insert malicious links as tracking URLs, or redirect customers to attacker-controlled courier portals.
Root Cause
The root cause is missing authorization on a state-changing REST endpoint. WordPress REST routes require an explicit permission_callback to gate writes. The plugin either returns __return_true or omits the check, leaving the route open to anonymous callers.
Attack Vector
The attack is network-based and requires no authentication or user interaction. An attacker enumerates or guesses sequential WooCommerce order IDs and sends crafted REST requests to the plugin's fulfillment endpoint. Each request overwrites the courier status and tracking fields for the targeted order.
No verified exploit code is published. See the WPScan Vulnerability Report for additional technical details.
Detection Methods for CVE-2026-89289
Indicators of Compromise
- Unexpected changes to WooCommerce order courier status or tracking URL fields without a corresponding admin action in the audit log.
- Anonymous POST requests to the Fast Courier plugin's REST route (/wp-json/) originating from unfamiliar IP addresses.
- Customer complaints referencing incorrect delivery status or unknown tracking links in order emails.
Detection Strategies
- Review WordPress and web server access logs for unauthenticated requests to Fast Courier REST endpoints and correlate with order modification timestamps.
- Enable WooCommerce order audit logging and alert on shop_order meta updates performed outside a logged-in session.
- Compare courier status values against the shipping provider's authoritative data to identify tampered records.
Monitoring Recommendations
- Deploy a web application firewall rule that requires authentication headers on write-method requests to /wp-json/ plugin namespaces.
- Monitor rate and volume of REST calls to Fast Courier endpoints and alert on sequential order id enumeration patterns.
- Track outbound tracking URLs for anomalous domains that differ from the configured courier provider.
How to Mitigate CVE-2026-89289
Immediate Actions Required
- Disable or deactivate the Fast Courier plugin until a fixed version is installed.
- Restrict access to /wp-json/ endpoints at the web server or WAF layer, allowing only authenticated or allow-listed sources.
- Audit recent WooCommerce orders for tampered tracking data and notify affected customers where appropriate.
Patch Information
No vendor-confirmed patched version is referenced in the NVD entry at publication. The vulnerability is reported as affecting the plugin through version 5.2.3. Monitor the WPScan Vulnerability Report and the WordPress plugin repository for an updated release addressing the missing authorization check.
Workarounds
- Block external access to the plugin's REST route via .htaccess, Nginx location rules, or WAF signatures until a patch is available.
- Use a WordPress security plugin to require authentication on all REST API write operations for plugin namespaces.
- Temporarily disable public-facing tracking display and reconcile fulfillment data manually from the courier provider's portal.
# Nginx example: block unauthenticated access to the Fast Courier REST namespace
location ~ ^/wp-json/fast-courier/ {
if ($request_method ~ ^(POST|PUT|PATCH|DELETE)$) {
return 403;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.