The WP EasyPay – Square for WordPress plugin for WordPress has a security vulnerability in versions 3.2.0 and earlier. This means that people who are not logged into the system could send a special request (called a Cross-Site Request Forgery) that would allow them to download information they should not have access to. This is because the plugin does not have a system in place to check that the request is legitimate. To protect yourself from this vulnerability, make sure you are using the most up-to-date version of the plugin.