← WordPress Vulnerabilities
WordPress security by component

FastPicker, an order picker and order management system (oms) for WooCommerce on steroids

FastPicker, an order picker and order management system (oms) for WooCommerce on steroids is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 09, 2026; the highest CVE/CNA score is 4.3.

Plugin slug: fastpicker

CVE-2026-8904: FastPicker, an order picker and order management system (oms) for WooCommerce on steroids: Cross-site request forgery

FastPicker, an order picker and order management system (oms) for WooCommerce on steroids is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 1.0.2.

PublishedJun 09, 2026
Known safe version> 1.0.2
Safe version
Jun 09, 2026 CVE-2026-8904
FastPicker, an order picker and order management system (oms) for WooCommerce on steroids: Cross-site request forgery
FastPicker, an order picker and order management system (oms) for WooCommerce on steroids is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 1.0.2.
> 1.0.2
CVE4.3
NVDPending