Indeed, there was a published SQL injection for this a while back. AFAIK, the add-on has been updated. You should likely revert to a pre-attack backup and then ensure XenForo and all add-ons are fully updated.
(Also, there's absolutely no reason to give the alleged person any publicity.)