Is my custom purchase feature creating a security vulnerability?

Thanks, terrible to hear but good to know …