WP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_profile_image (CVE-2026-10834) | HOL Guard CVE