The WP Travel Engine plugin for WordPress has a security issue called Stored Cross-Site Scripting. This affects versions up to 5.9.1 because the plugin does not properly clean up or protect the information that is entered or displayed. This means that someone with contributor-level access or higher can add harmful web scripts to pages, which will run when another user views the page.