The WP Hotel Booking plugin for WordPress has a security problem in versions up to and including 1.10.5. It is vulnerable to something called Cross-Site Request Forgery. This means that an unauthenticated attacker can use a fake request to make a site administrator do something