The WP Hotel Booking plugin used on WordPress websites may have a security issue that could allow unauthorized access to sensitive information or allow malicious code to be executed. This vulnerability affects versions 2.1.4 and below, and can be exploited by users with contributor-level access or higher. It allows them to include and run any files on the server, including PHP files, which can lead to bypassing security measures and gaining access to confidential data. This can happen even if the uploaded files are typically considered safe, such as images.