CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.
https://github.com/codelitdev/courselit/releases/tag/v0.57.5
https://github.com/codelitdev/courselit/pull/574/commits/5e11094df938e08485d0ab8aec2722c237ba0496