A popular plugin for WordPress called WP Travel, which helps with booking and managing tours, has a security vulnerability. This means that someone with access to the system can add their own code that can access private information from the database. The vulnerability is present in all versions up to and including 10.0.0. Attackers with at least Subscriber-level access can exploit this vulnerability.