The WP Hotel Booking plugin for WordPress had a security flaw in all versions up to 2.0.7 which allowed users who had an authenticated contributor-level access or higher to delete any post they wanted. A patch was released to prevent users with a lower access level from deleting posts, however it did not stop users with a higher access level from doing the same.