bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name (CVE-2026-101925) | HOL Guard CVE