The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.
https://wpscan.com/vulnerability/da611bd1-0702-4cdd-b04c-ad7210f78cfe/