The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.
https://wpscan.com/vulnerability/76856b3d-8f87-4d66-a22a-d65afa98c4ad/