The WP Travel Engine plugin for WordPress is at risk of being hacked through a process called SQL Injection. This can happen in versions up to and including 5.7.9 because the plugin does not properly protect against harmful code being added by users. As a result, someone with high-level access to the plugin can add their own code to extract private information from the database.