Impact
The Fast Courier plugin version 5.2.3 and earlier expose a REST route that accepts order updates without authenticating the caller. An unauthenticated attacker can specify any order ID and alter the courier status and the tracking information shown to customers, which can mislead recipients, hide fraudulent activity, and potentially cause revenue loss or damage to the merchant’s reputation. The vulnerability is a classic case of improper access control.
Affected Systems
Fast Courier WordPress plugin up to version 5.2.3. The flaw exists on any site that has the plugin installed and is connected to a WooCommerce order system. No other product or vendor is explicitly listed as affected.
Risk and Exploitability
The flaw can be exploited by sending a simple HTTP request to the order-status-update endpoint, requiring no authentication or special privileges. Because the endpoint is openly accessible and the plugin does not perform any credential checks, the attack complexity is low and the potential impact is high. The CVSS score is not disclosed, EPSS data is unavailable, and the vulnerability is not in the CISA KEV catalog, but the absence of authentication makes it a serious risk for any e‑commerce site using the plugin.
OpenCVE Enrichment