Fast Courier WordPress 插件在 5.2.3 版本及更早版本中存在漏洞,该漏洞未对未认证的 REST API 路由进行访问限制,该路由用于写入订单履行数据。攻击者无需认证即可通过提供任意 WooCommerce 订单的 ID,覆盖该订单的快递状态以及面向客户的物流跟踪详情。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Fast Courier | 0 ~ 5.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86786 | Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_ima | |
| CVE-2026-94299 | elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Cal | |
| CVE-2026-94270 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via | |
| CVE-2026-94278 | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat | |
| CVE-2026-94271 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverifi |
No comments yet