The plugin called WP Hotel Booking for WordPress has a security issue that could allow unauthorized people to access and change important data. This is because the plugin does not properly check for permissions when using certain functions and routes. This vulnerability exists in versions up to and including 2.0.9.2, and it could potentially expose sensitive information about bookings or allow them to be altered by someone who is not authenticated.