The WP Travel plugin for WordPress is not secure in versions up to 4.4.6. This is because it does not properly validate nonce on the save_meta_data() function. This means that unauthenticated attackers could potentially be able to save metadata for travel posts if they are able to trick a site administrator into clicking a link or performing another action.